Which of the following is an adaptive action that is configured by default for ES?
A.
Create notable event
B.
Create new correlation search
C.
Create investigation
D.
Create new asset
The Answer Is:
A
This question includes an explanation.
Explanation:
According to the Splunk Enterprise Security documentation, the Create Notable Event adaptive response action is one of the included adaptive response actions that is configured by default for ES. This action allows you to create a notable event from the results of a correlation search or from the details of another notable event. You can customize the title, description, urgency, owner, and other fields of the notable event. The Create Notable Event action is useful for creating alerts or tasks based on specific conditions or criteria. Therefore, the correct answer is A. Create notable event. References = Create Notable Event.
SPLK-3001 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"