問題1
In SPL, streaming commands operate on each individual event. There are two types of streaming commands: distributableand centralized. Which of the following statements is true about search efficiency using streaming commands?
In SPL, streaming commands operate on each individual event. There are two types of streaming commands: distributableand centralized. Which of the following statements is true about search efficiency using streaming commands?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題2
An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk ES?
An analyst needs to send notification emails after investigating a particular type of finding. Which feature should they ask an engineer to enable that will allow them to do so directly from Splunk ES?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題3
An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
正確答案: D
問題4
Which of the following is a tactic used by attackers, rather than a technique?
Which of the following is a tactic used by attackers, rather than a technique?
正確答案: A
問題5
During an investigation it is determined that an event is suspicious but expected in the environment. Out of the following, what is the best disposition to apply to this event?
During an investigation it is determined that an event is suspicious but expected in the environment. Out of the following, what is the best disposition to apply to this event?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題6
What is the main difference between hypothesis-driven and data-driven Threat Hunting?
What is the main difference between hypothesis-driven and data-driven Threat Hunting?
正確答案: A