Splunk Related Exams
SPLK-5001 Exam
What is the term for a model of normal network activity used to detect deviations?
While investigating findings in Enterprise Security, an analyst has identified a compromised device. Without leaving ES, what action could they take to run a sequence of containment activities on the compromised device that also updates the original finding?