Splunk Related Exams
SPLK-5001 Exam
The Lockheed Martin Cyber Kill Chain® breaks an attack lifecycle into several stages. A threat actor modified the registry on a compromised Windows system to ensure that their malware would automatically run at boot time. Into which phase of the Kill Chain would this fall?
According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?
The eval SPL expression supports many types of functions. Which of these function categories is not valid with eval?