Question 16

Which SPL syntax would be used to perform statistical queries on indexed fields to calculate the cumulative total risk by the system or user in the most efficient way?
  • Question 17

    What is the following step-by-step description an example of?
    1. The attacker devises a non-default beacon profile with Cobalt Strike and embeds this within a document.
    2. The attacker creates a unique email with the malicious document based on extensive research about their target.
    3. When the victim opens this document, a C2 channel is established to the attacker's temporary infrastructure on a compromised website.
  • Question 18

    What do frameworks and standards help accomplish in the cybersecurity landscape?
  • Question 19

    Which Splunk Enterprise Security framework provides a way to identify incidents from events and then manage the ownership, triage process, and state of those incidents?
  • Question 20

    A threat hunter creates a model of normal, expected activity on a portion of their network. Later, they compare observed activity against this model, looking for significant deviations. What is another name for this model?