The Cyber Landscape, Frameworks, and StandardsThreat and Attack Types, Motivations, and TacticsDefenses, Data Sources, and SIEM Best PracticesInvestigation, Event Handling, Correlation, and RiskSPL and Efficient SearchingThreat Hunting and Remediation
An analyst is examining a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, in which field would the IP address of the host from which the attacker is moving appear?
Ahost
Bdest
Csrc_nt_host
Dsrc_ip
A Cyber Threat Intelligence (CTI) team creates a report that describes a specific threat actor’s usual behaviors and intent. What type of intelligence does this represent?
AOperational
BExecutive
CTactical
DStrategic
An analyst wants to visualize threat objects throughout their environment and the chronological risk events for a Risk Object in Incident Review. Where can they access this?
ARunning the Risk Analysis Adaptive Response action within the Notable Event.
BVia a workflow action for the Risk Investigation dashboard.
CVia the Risk Analysis dashboard under the Security Intelligence tab in Enterprise Security.
DClicking the risk event count to open the Risk Event Timeline.
According to David Bianco’s Pyramid of Pain, which type of indicator is least effective for continuous monitoring?
ADomain names
BTTPs
CNetwork/Host artifacts
DHash values
QuestionQ6
Investigation, Event Handling, Correlation, and Risk
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Defenses, Data Sources, and SIEM Best Practices
QuestionQ8
Defenses, Data Sources, and SIEM Best Practices
QuestionQ9
Defenses, Data Sources, and SIEM Best Practices
QuestionQ10
Threat and Attack Types, Motivations, and Tactics
QuestionQ11
The Cyber Landscape, Frameworks, and Standards
QuestionQ12
Threat and Attack Types, Motivations, and Tactics
QuestionQ13
Defenses, Data Sources, and SIEM Best Practices
QuestionQ14
SPL and Efficient Searching
QuestionQ15
SPL and Efficient Searching
QuestionQ16
Threat Hunting and Remediation
QuestionQ17
Threat and Attack Types, Motivations, and Tactics
QuestionQ18
Threat and Attack Types, Motivations, and Tactics
QuestionQ19
Threat Hunting and Remediation
QuestionQ20
Threat and Attack Types, Motivations, and Tactics
QuestionQ21
Defenses, Data Sources, and SIEM Best Practices
QuestionQ22
The Cyber Landscape, Frameworks, and Standards
QuestionQ23
Threat and Attack Types, Motivations, and Tactics
QuestionQ24
Defenses, Data Sources, and SIEM Best Practices
QuestionQ25
Threat and Attack Types, Motivations, and Tactics
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
In Splunk Risk-Based Alerting, which term describes a set of conditions that dynamically adjusts risk scores for an entity, such as an asset or identity?
ARisk values
BRisk factors
CRisk entities
DRisk entries
During a malware-incident investigation, an analyst cannot identify the host name from the network logs. Which Enterprise Security feature most likely requires an update?
AMalware Center
BAssets & Identities
CIdentity Center
DData Models
Which of the following roles is commonly responsible for choosing and designing the infrastructure and tools that a security analyst uses to effectively perform their job duties?
ASecurity Engineer
BSOC Manager
CThreat Intelligence Analyst
DSecurity Architect
An organization uses Risk-Based Alerting (RBA). Over the last few days, a user account has generated multiple risk observations. What type of entity does Splunk call this account?
ARisk Factor
BRisk Index
CRisk Analysis
DRisk Object
Which TTP element represents an adversary’s goal—the reason for taking an action?
ATechnique
BProcedure
CTactic
DPurpose
Which phase comes first in the Continuous Monitoring cycle?
ARespond and Recover
BMonitor and Protect
CDefine and Predict
DAssess and Evaluate
Which of the following is an attacker tactic rather than a technique?
AGathering information about a target.
BEstablishing persistence with a scheduled task.
CUsing a phishing email to gain initial access.
DEscalating privileges via UAC bypass.
The United States Department of Defense (DoD) requires every government contractor to provide adequate security safeguards referenced in National Institute of Standards and Technology (NIST) 800-171. All DoD contractors must continuously reassess, monitor, and track compliance to remain eligible to do business with the US government.
Which Splunk Enterprise Security feature gives an analyst context for a correlation search’s mapping to the specific NIST guidelines?
AComments
BNotes
CAnnotations
DFramework mapping
An analyst is creating a search to examine Windows XML Event Logs, but the initial search returns no extracted fields. Based on the image above, what is the most likely cause?
AThe analyst does not have the proper role to search this data.
BThe analyst is searching newly indexed data that was improperly parsed.
CThe analyst did not add the extract command to their search pipeline.
DThe analyst is not in the proper Search Mode and should switch to Smart or Verbose.
In Splunk, which feature would an analyst use to drill down on an IP address field to query third-party intelligence about that IP?
ANotable drilldown
BAlert action
CWorkflow action
DAdaptive Response action
Which of the following use cases is most suitable for a Splunk SOAR playbook?
AForming hypothesis for Threat Hunting.
BVisualizing complex datasets.
CCreating persistent field extractions.
DTaking containment action on a compromised host.
An analyst has detected a possible Brute Force Dictionary Attack targeting several accounts in their directory. Which MITRE ATT&CK® Tactic is associated with this approach?
ACommand and Control
BPersistence
CInitial Access
DCredential Access
Attackers use this technique to conceal components such as programs, files, and network connections by hooking into the OS and intercepting system API calls. It can reside at either the user or kernel level. What technique is this?
ASpear phishing
BRootkit
CGuardrails
DSession hijacking
After a security incident, rotating the encryption keys used by a public web server is most closely associated with which security concept?
AIntegrity
BObfuscation
CAvailability
DConfidentiality
What does the following step-by-step description exemplify?
The attacker develops a non-default beacon profile with Cobalt Strike and embeds it in a document.
The attacker crafts a unique email containing the malicious document, based on extensive research about their target.
When the victim opens the document, a C2 channel is established to the attacker’s temporary infrastructure on a compromised website.
ATactic
BPolicy
CProcedure
DTechnique
The Security Operations Center (SOC) manager wants to create a new typosquatting dashboard following a successful campaign targeting a group of senior executives. Which existing ES dashboard could serve as the starting point for a custom dashboard?
AIAM Activity
BMalware Center
CAccess Anomalies
DNew Domain Analysis
A Cyber Threat Intelligence (CTI) team gives the CISO a briefing describing its view of the threat landscape facing the organization. What type of Threat Intelligence is this?
ATactical
BStrategic
COperational
DExecutive
The following list includes examples of Tactics, Techniques, and Procedures (TTPs):
Exploiting a remote service
Lateral movement
Using EternalBlue to exploit a remote SMB server
In what order are they listed?
ATactic, Technique, Procedure
BProcedure, Technique, Tactic
CTechnique, Tactic, Procedure
DTactic, Procedure, Technique
Which prepackaged app provides security content and detections on a regular, ongoing basis for Enterprise Security and SOAR?
ASSE
BESCU
CThreat Hunting
DInfoSec
An adversary uses "LoudMiner" to hijack resources for cryptocurrency mining. What does this represent within a TTP framework?
Community Discussion