ExamGecko
Question list
Search
Search

Question 57 - SPLK-2003 discussion

Report
Export

What are the differences between cases and events?

A.
Case: potential threats.Events: identified as a specific kind of problem and need a structured approach.
Answers
A.
Case: potential threats.Events: identified as a specific kind of problem and need a structured approach.
B.
Cases: only include high-level incident artifacts.Events: only include low-level incident artifacts.
Answers
B.
Cases: only include high-level incident artifacts.Events: only include low-level incident artifacts.
C.
Cases: contain a collection of containers.Events: contain potential threats.
Answers
C.
Cases: contain a collection of containers.Events: contain potential threats.
D.
Cases: incidents with a known violation and a plan for correction.Events: occurrences in the system that may require a response.
Answers
D.
Cases: incidents with a known violation and a plan for correction.Events: occurrences in the system that may require a response.
Suggested answer: C

Explanation:

In Splunk SOAR, an event is a security occurrence that may require a response. It is ingestedfrom a third-party source and can be labeled to group related events together. The default labelfor containers is ''Events,'' which signifies potential threats13. A case, on the other hand, is acontainer that holds several containers, consolidating multiple events into one logicalmanagement unit. Cases can include artifacts and external evidence such as screen captures,analyst notes, and event data from third-party products22. They are used to manage andanalyze investigation data tied to specific security events and incidents, providing a structuredapproach to incident response34.Manage the status, severity, and resolution of events in Splunk SOAR (Cloud) - SplunkDocumentationManaging cases in SOAR - Splunk LanternWhat is Splunk Phantom (Renamed to Splunk SOAR)? - BlueVoyantOverview of cases - Splunk Documentation

asked 23/09/2024
Tania Trif
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first