問題文
A financial services SOC wants its correlation searches to carry mappings to more than one industry framework so that different audiences can read the same alert. Which statements correctly describe what the Annotations section of a correlation search in Splunk Enterprise Security supports? (Select two.)
選択肢
- Several named frameworks can be annotated on the same correlation search, including CIS 20, the Lockheed Martin Cyber Kill Chain, MITRE ATT&CK, and NIST.
- The annotated values appear as field labels when an analyst looks at the resulting alert, so the framework context travels with the alert into triage.
- Annotating a correlation search automatically adds it to the use case library so that the framework filter can find it without any further work from the engineer.
- The annotation replaces the severity value that the correlation search assigns, so the framework mapping is what drives the urgency of the resulting alert.
- Only the frameworks that ship with predefined values can be annotated; a SOC that uses an internal control catalog has to keep that mapping outside Splunk in a separate document.