Splunk Related Exams
SPLK-5001 Exam
An analyst investigates an IDS alert and confirms suspicious traffic to a known malicious IP. What Enterprise Security data model would they use to investigate which process initiated the network connection?
What goal of an Advanced Persistent Threat (APT) group aims to disrupt or damage on behalf of a cause?
In which phase of the Continuous Monitoring cycle are suggestions and improvements typically made?