Question 6

There are many resources for assisting with SPL and configuration questions. Which of the following resources feature community-sourced answers?
  • Question 7

    A threat hunter executed a hunt based on the following hypothesis:
    As an actor, I want to plant rundll32 for proxy execution of malicious code and leverage Cobalt Strike for Command and Control.
    Relevant logs and artifacts such as Sysmon, netflow, IDS alerts, and EDR logs were searched, and the hunter is confident in the conclusion that Cobalt Strike is not present in the company's environment.
    Which of the following best describes the outcome of this threat hunt?
  • Question 8

    An organization is using Risk-Based Alerting (RBA). During the past few days, a user account generated multiple risk observations. Splunk refers to this account as what type of entity?
  • Question 9

    An analysis of an organization's security posture determined that a particular asset is at risk and a new process or solution should be implemented to protect it. Typically, who would be in charge of designing the new process and selecting the required tools to implement it?
  • Question 10

    During their shift, an analyst receives an alert about an executable being run from C:\Windows\Temp. Why should this be investigated further?