Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Splunk SPLK-2003 Exam - Topic 7 Question 84 Discussion

Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?
D) Use the Upload action of the Secure Store app to store the file in the database.
A) Copy/paste the attachment into a note.
B) Add a link to the file in a new artifact.
C) Use the Files tab on the Investigation page to upload the attachment.

Splunk SPLK-2003 Exam - Topic 7 Question 84 Discussion

Actual exam question for Splunk's SPLK-2003 exam
Question #: 84
Topic #: 7
[All SPLK-2003 Questions]

Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?

Show Suggested Answer Hide Answer
Suggested Answer: D

To securely store a compressed version of an email attachment suspected of containing malware for future analysis, the most effective approach within Splunk SOAR is to use the Upload action of the Secure Store app. This app is specifically designed to handle sensitive or potentially dangerous files by securely storing them within the SOAR database, allowing for controlled access and analysis at a later time. This method ensures that the file is not only safely contained but also available for future forensic or investigative purposes without risking exposure to the malware. Options A, B, and C do not provide the same level of security and functionality for handling suspected malware files, making option D the most appropriate choice.

Secure Store app is a SOAR app that allows you to store files securely in the SOAR database. The Secure Store app provides two actions: Upload and Download. The Upload action takes a file as an input and stores it in the SOAR database in a compressed and encrypted format. The Download action takes a file ID as an input and retrieves the file from the SOAR database and decrypts it. The Secure Store app can be used to store files that contain sensitive or malicious data, such as email attachments with suspected malware, for future analysis. Therefore, option D is the correct answer, as it states the action that will store a compressed, secure version of an email attachment with suspected malware for future analysis. Option A is incorrect, because copying and pasting the attachment into a note will not store the file securely, but rather expose the file content to anyone who can view the note. Option B is incorrect, because adding a link to the file in a new artifact will not store the file securely, but rather create a reference to the file location, which may not be accessible or reliable. Option C is incorrect, because using the Files tab on the Investigation page to upload the attachment will not store the file securely, but rather store the file in the SOAR file system, which may not be encrypted or compressed.


Contribute your Thoughts:

0/2000 characters
Gracia
2 hours ago
I remember a similar question where we had to choose between storing methods, and I think D was the right choice there too.
upvoted 0 times
...
Rose
5 days ago
I’m leaning towards C, but I can't recall if it specifically mentioned compression or security features.
upvoted 0 times
...
Carmelina
10 days ago
I feel like we discussed the Files tab option before, but it seems more like a way to just upload files rather than secure them.
upvoted 0 times
...
Mila
16 days ago
I think the answer might be D, but I'm not entirely sure. I remember something about secure storage in our last practice session.
upvoted 0 times
...

Save Cancel