ExamGecko
Question list
Search
Search

Question 47 - SPLK-2003 discussion

Report
Export

Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?

A.
Notes
Answers
A.
Notes
B.
Actions
Answers
B.
Actions
C.
Service level agreement (SLA) expiration
Answers
C.
Service level agreement (SLA) expiration
D.
Playbooks
Answers
D.
Playbooks
Suggested answer: D

Explanation:

The severity of a container in Splunk Phantom can be set manually or automatically during theingestion process. In addition to these methods, playbooks can also change the severity of acontainer. Playbooks are automated workflows that define a series of actions based on certaintriggers and conditions. Within a playbook, actions can be defined to adjust the severity level ofa container depending on the analysis of the event data, the outcome of actions taken, or othercontextual factors. This dynamic adjustment allows for a more accurate and responsive incidentprioritization as new information becomes available during the investigation process.

asked 23/09/2024
Brent Kehoe
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first