Splunk Related Exams
SPLK-5001 Exam
The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
Which of the following is not a component of the Splunk Security Content library (ESCU, SSE)?
The Lockheed Martin Cyber Kill Chain® breaks an attack lifecycle into several stages. A threat actor modified the registry on a compromised Windows system to ensure that their malware would automatically run at boot time. Into which phase of the Kill Chain would this fall?