This is a tricky one. There are a lot of nuances to consider around the relationship between the independent and internal auditors. I'll need to draw on my understanding of auditing standards and best practices to reason through the most appropriate answer here.
C seems like the right answer. CEF fields are mapped to CIM, and the container is created on the Splunk server. That seems more in line with how the Splunk app would function.
Option A makes the most sense to me. CEF fields are mapped to CIM fields, and a container is created on the SOAR server. That's how I would expect the integration to work.
I think the correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. The SOAR app should be handling the translation between the different field formats.
Mila
5 months agoMerlyn
5 months agoMalcolm
6 months agoBarrie
6 months agoNan
6 months agoGeorgene
6 months agoAlmeta
6 months agoMa
6 months agoSabra
6 months agoMammie
6 months agoEvangelina
6 months agoBernardo
11 months agoTiera
11 months agoDemetra
9 months agoStefan
9 months agoCasey
10 months agoFrancine
11 months agoVonda
11 months agoCasie
10 months agoEloisa
10 months agoOwen
10 months agoAlyssa
12 months agoJoana
11 months agoLenna
11 months agoDyan
12 months agoTeresita
1 year agoGeoffrey
1 year agoEura
10 months agoNoe
11 months agoSuzi
11 months agoJusta
11 months agoDyan
1 year ago