Public-works leadership calls MFA a framework and MITRE ATT&CK a control. How should the analyst correct that mix-up and place Splunk?
Select an answer to reveal the explanation.
Short Explanation
A framework is the map; a control is a lock on a door. ATT&CK, NIST CSF, and CIS are maps, while MFA, logging, and segmentation are locks. Splunk reads those lock logs so the SOC can prove and hunt — it does not become the map or the lock.
Full Explanation
Industry frameworks (MITRE ATT&CK, NIST CSF, CIS Controls) organize how teams talk about threats and safeguards. Individual controls — MFA, logging, network segmentation — are the safeguards themselves. Splunk Enterprise Security consumes the logs those controls produce and maps detections to frameworks; it is the evidence and analytics layer, not a replacement framework and not MFA. Conflating the two words is the mix-up the item is written to catch.