Splunk Certified Cybersecurity Defense Analyst - SPLK-5001무료 덤프문제 풀어보기
Associated with the behavior of a threat actor and a structured framework for executing a cyberattack, which of the following terms defines exactly how a threat actor achieves a tactical goal?
정답: D
설명: (Fast2test 회원만 볼 수 있음)
A threat hunter is analyzing incoming emails during the past 30 days, looking for spam or phishing campaigns targeting many users. This involves finding large numbers of similar, but not necessarily identical, emails.
The hunter extracts key datapoints from each email record, including the sender's address, recipient's address, subject, embedded URLs, and names of any attachments. Using the Splunk App for Data Science and Deep Learning, they then visualize each of these messages as points on a graph, looking for large numbers of points that occur close together.
This is an example of what type of threat-hunting technique?
The hunter extracts key datapoints from each email record, including the sender's address, recipient's address, subject, embedded URLs, and names of any attachments. Using the Splunk App for Data Science and Deep Learning, they then visualize each of these messages as points on a graph, looking for large numbers of points that occur close together.
This is an example of what type of threat-hunting technique?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?
정답: B
Which of the TTP elements represent the adversary's goal - the reason for performing an action?
정답: D
설명: (Fast2test 회원만 볼 수 있음)
An analyst discovers she has only raw data from a source. She believes that it could be of great value to future analysis efforts if it were available to existing correlation searches and reports.
What process should the analyst suggest be performed for that source?
What process should the analyst suggest be performed for that source?
정답: B
설명: (Fast2test 회원만 볼 수 있음)
The Security Operations team would like to track improvements after customizing dashboards to help analysts triage security alerts more efficiently. Which metric would they use?
정답: D