What is the following step-by-step description an example of?
The attacker devises a non-default beacon profile with Cobalt Strike and embeds this within a document.
The attacker creates a unique email with the malicious document based on extensive research about their target.
When the victim opens this document, a C2 channel is established to the attacker’s temporary infrastructure on a compromised website.
ATactic
BPolicy
CProcedure
DTechnique
A Cyber Threat Intelligence (CTI) team produces a report detailing a specific threat actor’s typical behaviors and intent. This would be an example of what type of intelligence?
AOperational
BExecutive
CTactical
DStrategic
Which Enterprise Security framework provides a mechanism for running preconfigured actions within the Splunk platform or integrating with external applications?
AAsset and Identity
BNotable Event
CThreat Intelligence
DAdaptive Response
A Risk Rule generates events on Suspicious Cloud Share Activity and regularly contributes to confirmed incidents from Risk Notables. An analyst realizes the raw logs these events are generated from contain information which helps them determine what might be malicious.
What should they ask their engineer for to make their analysis easier?
ACreate a field extraction for this information.
BAdd this information to the risk_message.
CCreate another detection for this information.
DAllowlist more events based on this information.
Question 6
Investigation, Event Handling, Correlation, and Risk
0
Question 7
Threat and Attack Types, Motivations, and Tactics
Question 8
Defenses, Data Sources, and SIEM Best Practices
Question 9
SPL and Efficient Searching
Question 10
SPL and Efficient Searching
Question 11
Threat and Attack Types, Motivations, and Tactics
Question 12
Threat Hunting and Remediation
Question 13
Threat and Attack Types, Motivations, and Tactics
Question 14
The Cyber Landscape, Frameworks, and Standards
Question 15
Defenses, Data Sources, and SIEM Best Practices
Question 16
Threat and Attack Types, Motivations, and Tactics
Question 17
Investigation, Event Handling, Correlation, and Risk
Question 18
Defenses, Data Sources, and SIEM Best Practices
Question 19
The Cyber Landscape, Frameworks, and Standards
Question 20
Threat Hunting and Remediation
Question 21
SPL and Efficient Searching
Question 22
SPL and Efficient Searching
Question 23
Investigation, Event Handling, Correlation, and Risk
Question 24
Threat Hunting and Remediation
Question 25
SPL and Efficient Searching
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain® to be mapped to Correlation Search results?
AAnnotations
BPlaybooks
CComments
DEnrichments
Upon investigating a report of a web server becoming unavailable, the security analyst finds that the web server’s access log has the same log entry millions of times:
147.186.119.200 - - [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733
What kind of attack is occurring?
ADenial of Service Attack
BDistributed Denial of Service Attack
CCross-Site Scripting Attack
DDatabase Injection Attack
The United States Department of Defense (DoD) requires all government contractors to provide adequate security safeguards referenced in National Institute of Standards and Technology (NIST) 800-171. All DoD contractors must continually reassess, monitor, and track compliance to be able to do business with the US government.
Which feature of Splunk Enterprise Security provides an analyst context for the correlation search mapping to the specific NIST guidelines?
AComments
BNotes
CAnnotations
DFramework mapping
Which of the following is a best practice for searching in Splunk?
AStreaming commands run before aggregating commands in the Search pipeline.
BRaw word searches should contain multiple wildcards to ensure all edge cases are covered.
CLimit fields returned from the search utilizing the table command.
DSearching over All Time ensures that all relevant data is returned.
Which of the following is the primary benefit of using the CIM in Splunk?
AIt allows for easier correlation of data from different sources.
BIt improves the performance of search queries on raw data.
CIt enables the use of advanced machine learning algorithms.
DIt automatically detects and blocks cyber threats.
Tactics, Techniques, and Procedures (TTPs) are methods or behaviors utilized by attackers. In which framework are these categorized?
ANIST 800-53
BISO 27000
CCIS18
DMITRE ATT&CK
A threat hunter executed a hunt based on the following hypothesis:
As an actor, I want to plant rundll32 for proxy execution of malicious code and leverage Cobalt Strike for Command and Control.
Relevant logs and artifacts such as Sysmon, netflow, IDS alerts, and EDR logs were searched, and the hunter is confident in the conclusion that Cobalt Strike is not present in the company’s environment.
Which of the following best describes the outcome of this threat hunt?
AThe threat hunt was successful because the hypothesis was not proven.
BThe threat hunt failed because the hypothesis was not proven.
CThe threat hunt failed because no malicious activity was identified.
DThe threat hunt was successful in providing strong evidence that the tactic and tool is not present in the environment.
An analyst notices that one of their servers is sending an unusually large amount of traffic, gigabytes more than normal, to a single system on the Internet. There doesn’t seem to be any associated increase in incoming traffic.
What type of threat actor activity might this represent?
AData exfiltration
BNetwork reconnaissance
CData infiltration
DLateral movement
In which phase of the Continuous Monitoring cycle are suggestions and improvements typically made?
ADefine and Predict
BEstablish and Architect
CAnalyze and Report
DImplement and Collect
An analyst is not sure that all of the potential data sources at her company are being correctly or completely utilized by Splunk and Enterprise Security. Which of the following might she suggest using, in order to perform an analysis of the data types available and some of their potential security uses?
ASplunk ITSI
BSplunk Security Essentials
CSplunk SOAR
DSplunk Intelligence Management
During their shift, an analyst receives an alert about an executable being run from C:\Windows\Temp. Why should this be investigated further?
ATemp directories aren’t owned by any particular user, making it difficult to track the process owner when files are executed.
BTemp directories are flagged as non-executable, meaning that no files stored within can be executed, and this executable was run from that directory.
CTemp directories contain the system page file and the virtual memory file, meaning the attacker can use their malware to read the in memory values of running programs.
DTemp directories are world writable thus allowing attackers a place to drop, stage, and execute malware on a system without needing to worry about file permissions.
An analyst would like to visualize threat objects across their environment and chronological risk events for a Risk Object in Incident Review. Where would they find this?
ARunning the Risk Analysis Adaptive Response action within the Notable Event.
BVia a workflow action for the Risk Investigation dashboard.
CVia the Risk Analysis dashboard under the Security Intelligence tab in Enterprise Security.
DClicking the risk event count to open the Risk Event Timeline.
What device typically sits at a network perimeter to detect command and control and other potentially suspicious traffic?
AHost-based firewall
BWeb proxy
CEndpoint Detection and Response
DIntrusion Detection System
According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?
ADomain names
BTTPs
CNetwork/Host artifacts
DHash values
An analysis of an organization’s security posture determined that a particular asset is at risk and a new process or solution should be implemented to protect it. Typically, who would be in charge of implementing the new process or solution that was selected?
ASecurity Architect
BSOC Manager
CSecurity Engineer
DSecurity Analyst
Which of the following is a correct Splunk search that will return results in the most performant way?
Aindex=foo host=i-478619733 | stats range(_time) as duration by src_ip | bin duration span=5min | stats count by duration, host
B| stats range(_time) as duration by src_ip | index=foo host=i-478619733 | bin duration span=5min | stats count by duration, host
Cindex=foo host=i-478619733 | transaction src_ip |stats count by host
There are many resources for assisting with SPL and configuration questions. Which of the following resources feature community-sourced answers?
ASplunk Answers
BSplunk Lantern
CSplunk Guidebook
DSplunk Documentation
A successful Continuous Monitoring initiative involves the entire organization. When an analyst discovers the need for more context or additional information, perhaps from additional data sources or altered correlation rules, to what role would this request generally escalate?
ASOC Manager
BSecurity Analyst
CSecurity Engineer
DSecurity Architect
Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?
AThreat Intelligence Framework
BRisk Framework
CNotable Event Framework
DAsset and Identity Framework
While the top command is utilized to find the most common values contained within a field, a Cyber Defense Analyst hunts for anomalies. Which of the following Splunk commands returns the least common values?