EC-Council
312-39 · Question #166
John, SOC analyst wants to monitor the attempt of process creation activities from any of their Windows endpoints. Which of following Splunk query will help him to fetch related logs associated with p
Sign in or unlock 312-39 to reveal the answer and full explanation for question #166. The question stem and answer options stay visible for context.
Security Incident Detection
Question
John, SOC analyst wants to monitor the attempt of process creation activities from any of their Windows endpoints. Which of following Splunk query will help him to fetch related logs associated with process creation?
Options
- Aindex=windows LogName=Security EventCode=4678 NOT (Account_Name=*$) .. .. ... ..
- Bindex=windows LogName=Security EventCode=4688 NOT (Account_Name=*$) .. .. ..
- Cindex=windows LogName=Security EventCode=3688 NOT (Account_Name=*$) .. .. ..
- Dindex=windows LogName=Security EventCode=5688 NOT (Account_Name=*$) ... ... ...
Unlock 312-39 to see the answer
You've previewed enough free 312-39 questions. Unlock 312-39 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Splunk queries#Windows Event ID 4688#process creation#SIEM