SPLK-5001 · Question #28
The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
The correct answer is D. Endpoint. Option D (Endpoint) is correct because the file_acl field belongs to the Endpoint data model, specifically within its Filesystem dataset, which captures file-level attributes including permissions and access controls on host systems. The Malware data model focuses on malicious…
Question
The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
Options
- AMalware
- BAlerts
- CVulnerabilities
- DEndpoint
How the community answered
(35 responses)- A9% (3)
- B3% (1)
- C3% (1)
- D86% (30)
Explanation
Option D (Endpoint) is correct because the file_acl field belongs to the Endpoint data model, specifically within its Filesystem dataset, which captures file-level attributes including permissions and access controls on host systems. The Malware data model focuses on malicious software detections and behaviors, not file metadata like ACLs. The Alerts data model aggregates notable events and triggered alerts, without storing granular file attribute fields. The Vulnerabilities data model covers vulnerability scan results and CVE data, which is unrelated to file access controls.
Memory tip: Think "Endpoint = everything on the machine" - files, processes, ports, registry, and their attributes (like ACLs) all live in the Endpoint data model because they describe the state of a host system.
Topics
Community Discussion
No community discussion yet for this question.