Q: 1
An analyst is not sure that all of the potential data sources at her company are being correctly or
completely utilized by Splunk and Enterprise Security. Which of the following might she suggest
using, in order to perform an analysis of the data types available and some of their potential security
uses?
Options
Discussion
I don’t think it’s D. B covers data source analysis with that Data Source Check feature. The others are more about automation or threat intel, not mapping your existing data. Trap is thinking D helps here.
Option D? Not really sure since Splunk Intelligence Management deals with external threat intel feeds, but maybe it can show data types too? Feels like a toss up for me, can someone confirm?
I’ve seen similar questions and B is the way to go. Security Essentials has that data source check so it shows what you have and maps it to use cases. Pretty sure the others don’t do this directly, correct me if I’m wrong.
Be respectful. No spam.
Question 1 of 15