Question 6

Which of the following is a best practice for searching in Splunk?
  • Question 7

    Which part of the CIA triad is the opposite of destruction of information?
  • Question 8

    Which of the following is a best practice when creating performant searches within Splunk?
  • Question 9

    An analyst learns that several types of data are being ingested into Splunk and Enterprise Security, and wants to use the metadata SPL command to list them in a search. Which of the following arguments should she use?
  • Question 10

    An IDS signature is designed to detect and alert on logins to a certain server, but only if they occur from 6:00 PM - 6:00 AM. If no IDS alerts occur in this window, but the signature is known to be correct, this would be an example of what?