This is a tricky one. There are a lot of nuances to consider around the relationship between the independent and internal auditors. I'll need to draw on my understanding of auditing standards and best practices to reason through the most appropriate answer here.
C seems like the right answer. CEF fields are mapped to CIM, and the container is created on the Splunk server. That seems more in line with how the Splunk app would function.
Option A makes the most sense to me. CEF fields are mapped to CIM fields, and a container is created on the SOAR server. That's how I would expect the integration to work.
I think the correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. The SOAR app should be handling the translation between the different field formats.
Mila
7 months agoMerlyn
7 months agoMalcolm
7 months agoBarrie
7 months agoNan
7 months agoGeorgene
8 months agoAlmeta
8 months agoMa
8 months agoSabra
8 months agoMammie
8 months agoEvangelina
8 months agoBernardo
1 year agoTiera
1 year agoDemetra
11 months agoStefan
11 months agoCasey
11 months agoFrancine
1 year agoVonda
1 year agoCasie
12 months agoEloisa
12 months agoOwen
12 months agoAlyssa
1 year agoJoana
1 year agoLenna
1 year agoDyan
1 year agoTeresita
1 year agoGeoffrey
1 year agoEura
12 months agoNoe
1 year agoSuzi
1 year agoJusta
1 year agoDyan
1 year ago