Question 1

This cyber framework provides guidance on how to approach cybersecurity related issues based on four main use cases: threat intelligence, detection and analytics, adversary emulation and red teaming, and assessment and engineering. Which framework is this?
  • Question 2

    Which Security Domain in Enterprise Security contains the dashboards that include vulnerability information generated by vulnerability scanners, next-generation firewalls, and other security devices?
  • Question 3

    In Splunk, what feature would an analyst leverage to drilldown on an IP address field to query third-party intelligence for that IP?
  • Question 4

    According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?
  • Question 5

    Enterprise Security has been configured to generate a Notable Event when a user has quickly authenticated from multiple locations between which travel would be impossible. This would be considered what kind of an anomaly?