Exam Name: | Splunk Certified Cybersecurity Defense Analyst | ||
Exam Code: | SPLK-5001 Dumps | ||
Vendor: | Splunk | Certification: | Cybersecurity Defense Analyst |
Questions: | 99 Q&A's | Shared By: | aaminah |
Which stage of continuous monitoring involves adding data, creating detections, and building drilldowns?
A Risk Rule generates events on Suspicious Cloud Share Activity and regularly contributes to confirmed incidents from Risk Notables. An analyst realizes the raw logs these events are generated from contain information which helps them determine what might be malicious.
What should they ask their engineer for to make their analysis easier?
Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?
Upon investigating a report of a web server becoming unavailable, the security analyst finds that the web server’s access log has the same log entry millions of times:
147.186.119.200 - - [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733
What kind of attack is occurring?