Question 26

During an investigation it is determined that an event is suspicious but expected in the environment. Out of the following, what is the best disposition to apply to this event?
  • Question 27

    Which of the following data sources would be most useful to determine if a user visited a recently identified malicious website?
  • Question 28

    There are different metrics that can be used to provide insights into SOC operations. If Mean Time to Respond is defined as the total time it takes for an Analyst to disposition an event, what is the typical starting point for calculating this metric for a particular event?
  • Question 29

    Which of the following is a correct Splunk search that will return results in the most performant way?
  • Question 30

    How are SOAR playbooks used in threat hunting?