A city analyst must request a new correlation search for permitting-portal account-takeover signals. What understanding is enough for that request without becoming the Enterprise Security administrator?
Select an answer to reveal the explanation.
Short Explanation
The analyst does not have to weld the search together, but they do have to order the right parts. Fields, object type, trigger, and whether it writes risk or a notable—that is the shopping list. Leave cluster math and playbook code to the other certifications.
Full Explanation
Creating correlation searches is primarily an engineer task, but defense analysts must understand the moving parts well enough to request the right content. That includes the CIM fields to detect, the risk object type, trigger conditions, and which adaptive responses should fire. Enterprise Security app administration, indexer sizing, and SOAR playbook authoring are out of scope for SPLK-5001. The exam tests that analyst-level request, not admin XML.