A library SOC analyst needs to run ping or send a notable to SOAR from a correlation search or from an open notable. Which ES construct is that action framework?
Select an answer to reveal the explanation.
Short Explanation
Adaptive Response is the action button on the alert, not a Windows service hiding on the clerk PC. From a search or from the notable, ES can create a notable, write risk, ping, email, or hand off to SOAR. You do not have to write the Python playbook on this exam.
Full Explanation
Adaptive Response Actions are Enterprise Security alert actions that conform to the common action model. They can be invoked automatically from a correlation search or ad hoc from a notable or finding. Typical actions include creating a notable, risk analysis, ping, nbtstat, nslookup, send email, and send to SOAR. They are not a Windows service, a dashboard, or SOAR playbook authoring, which sits outside SPLK-5001 analyst scope.