フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 20 / 20 問目

問題文

A SOC has both adaptive response actions on its detections and playbooks in Splunk SOAR. Which statements correctly describe the relationship? (Select two.)

選択肢

  1. Playbooks are built in the automation product and can be run against an investigation, either automatically for the investigation type or by an analyst on demand.
  2. Playbooks replace adaptive response actions, so a SOC that has the automation product does not need to configure any actions on its detections.
  3. Adaptive response actions can contain conditional branching and multiple steps in the same way playbooks can.
  4. Response actions attached to a detection run in response to that detection matching, without any analyst involvement.
  5. A playbook can only be triggered by an adaptive response action, so every playbook the SOC wants to run has to be attached to a detection first and there is no path for an analyst to start one during an investigation that was opened manually.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。