Question 11

Which of the following is a best practice for searching in Splunk?
  • Question 12

    Which search command allows an analyst to match whatever is inside the parentheses as a single term in the index, even if it contains characters that are usually recognized as minor breakers such as periods or underscores?
  • Question 13

    Which of the following use cases is best suited to be a Splunk SOAR Playbook?
    A Forming hypothesis for Threat Hunting
    B. Visualizing complex datasets.
    C. Creating persistent field extractions.
    D. Taking containment action on a compromised host

    Question 14

    An analyst would like to test how certain Splunk SPL commands work against a small set of dat a. What command should start the search pipeline if they wanted to create their own data instead of utilizing data contained within Splunk?
  • Question 15

    An analyst is looking at Web Server logs, and sees the following entry as the last web request that a server processed before unexpectedly shutting down:
    147.186.119.107 - - [28/Jul/2006:10:27:10 -0300] "POST /cgi-bin/shutdown/ HTTP/1.0" 200 3333 What kind of attack is most likely occurring?