nerdexam
Splunk

SPLK-5001 · Question #114

A threat hunter is analyzing incoming emails during the past 30 days, looking for spam or phishing campaigns targeting many users. This involves finding large numbers of similar, but not necessarily…

The correct answer is B. Clustering. By representing each email as a point in a multi‑dimensional space (based on sender, recipient, subject, URLs, attachments, etc.) and then identifying groups of points that lie close together, the hunter is using clustering to find batches of similar emails indicative of a…

Threat Detection and Alerting

Question

A threat hunter is analyzing incoming emails during the past 30 days, looking for spam or phishing campaigns targeting many users. This involves finding large numbers of similar, but not necessarily identical, emails. The hunter extracts key datapoints from each email record, including the sender's address, recipient's address, subject, embedded URLs, and names of any attachments. Using the Splunk App for Data Science and Deep Learning, they then visualize each of these messages as points on a graph, looking for large numbers of points that occur close together. This is an example of what type of threat-hunting technique?

Options

  • ATime Series Analysis
  • BClustering
  • CLeast Frequency of Occurrence Analysis
  • DMost Frequency of Occurrence Analysis

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    85% (17)
  • C
    5% (1)

Explanation

By representing each email as a point in a multi‑dimensional space (based on sender, recipient, subject, URLs, attachments, etc.) and then identifying groups of points that lie close together, the hunter is using clustering to find batches of similar emails indicative of a campaign.

Topics

#clustering#machine learning#phishing detection#threat hunting

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice