This is a tricky one. There are a lot of nuances to consider around the relationship between the independent and internal auditors. I'll need to draw on my understanding of auditing standards and best practices to reason through the most appropriate answer here.
C seems like the right answer. CEF fields are mapped to CIM, and the container is created on the Splunk server. That seems more in line with how the Splunk app would function.
Option A makes the most sense to me. CEF fields are mapped to CIM fields, and a container is created on the SOAR server. That's how I would expect the integration to work.
I think the correct answer is B. CIM fields are mapped to CEF fields and a container is created on the SOAR server. The SOAR app should be handling the translation between the different field formats.
Mila
4 months agoMerlyn
4 months agoMalcolm
4 months agoBarrie
4 months agoNan
4 months agoGeorgene
5 months agoAlmeta
5 months agoMa
5 months agoSabra
5 months agoMammie
5 months agoEvangelina
5 months agoBernardo
9 months agoTiera
9 months agoDemetra
8 months agoStefan
8 months agoCasey
8 months agoFrancine
9 months agoVonda
9 months agoCasie
9 months agoEloisa
9 months agoOwen
9 months agoAlyssa
10 months agoJoana
9 months agoLenna
10 months agoDyan
10 months agoTeresita
11 months agoGeoffrey
11 months agoEura
9 months agoNoe
9 months agoSuzi
10 months agoJusta
10 months agoDyan
11 months ago