nerdexam
Splunk

SPLK-5001 · Question #107

Which of the following data sources would be most useful to determine if a user visited a recently identified malicious website?

The correct answer is B. Web Proxy Logs. Web proxy logs capture every user request to external websites, allowing you to see if a user’s browser was directed to the known malicious URL. Proxy logs thus provide direct evidence of web visits, unlike web server logs (which only cover your own servers) or IDS/AD logs.

Security Data Onboarding and Normalization

Question

Which of the following data sources would be most useful to determine if a user visited a recently identified malicious website?

Options

  • AWeb Server Logs
  • BWeb Proxy Logs
  • CIntrusion Detection Logs
  • DActive Directory Logs

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    91% (21)
  • C
    4% (1)

Explanation

Web proxy logs capture every user request to external websites, allowing you to see if a user’s browser was directed to the known malicious URL. Proxy logs thus provide direct evidence of web visits, unlike web server logs (which only cover your own servers) or IDS/AD logs.

Topics

#web proxy logs#data sources#malicious website detection#network traffic

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice