Question 16

Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain to be mapped to Correlation Search results?
  • Question 17

    An analyst is examining the logs for a web application's login form. They see thousands of failed logon attempts using various usernames and passwords. Internet research indicates that these credentials may have been compiled by combining account information from several recent data breaches.
    Which type of attack would this be an example of?
  • Question 18

    What is the following step-by-step description an example of?
    1. The attacker devises a non-default beacon profile with Cobalt Strike and embeds this within a document.
    2. The attacker creates a unique email with the malicious document based on extensive research about their target.
    3. When the victim opens this document, a C2 channel is established to the attacker's temporary infrastructure on a compromised website.
  • Question 19

    The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
  • Question 20

    What is the main difference between hypothesis-driven and data-driven Threat Hunting?