Splunk SPLK-5001 Exam - Topic 8 Question 30 Discussion
While investigating findings in Enterprise Security, an analyst has identified a compromised device. Without leaving ES, what action could they take to run a sequence of containment activities on the compromised device that also updates the original finding?
C) Run an adaptive response action that initiates a SOAR playbook.
A) Run an event-level workflow action that initiates a SOAR playbook.
B) Run a field-level workflow action that initiates a SOAR playbook.
D) Run an alert action that initiates a SOAR playbook.
Anisha
3 months agoHelene
3 months agoDestiny
3 months agoPauline
4 months agoBarney
4 months agoBrice
4 months agoZona
5 months agoKiera
5 months agoMalissa
5 months agoJeffrey
5 months agoTiera
5 months agoKaycee
5 months agoJacquelyne
6 months agoFreeman
6 months agoJules
6 months agoCelestina
6 months agoMickie
6 months agoNieves
6 months agoSelene
7 months agoDominga
7 months agoMargarett
7 months agoNichelle
7 months agoFrancoise
7 months agoDorothy
8 months agoCamellia
8 months agoKeneth
2 months agoTruman
2 months agoCortney
3 months agoOlive
3 months agoMakeda
3 months ago