nerdexam
Splunk

SPLK-5001 · Question #28

The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?

The correct answer is D. Endpoint. Option D (Endpoint) is correct because the file_acl field belongs to the Endpoint data model, specifically within its Filesystem dataset, which captures file-level attributes including permissions and access controls on host systems. The Malware data model focuses on malicious…

Security Data Onboarding and Normalization

Question

The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?

Options

  • AMalware
  • BAlerts
  • CVulnerabilities
  • DEndpoint

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    86% (30)

Explanation

Option D (Endpoint) is correct because the file_acl field belongs to the Endpoint data model, specifically within its Filesystem dataset, which captures file-level attributes including permissions and access controls on host systems. The Malware data model focuses on malicious software detections and behaviors, not file metadata like ACLs. The Alerts data model aggregates notable events and triggered alerts, without storing granular file attribute fields. The Vulnerabilities data model covers vulnerability scan results and CVE data, which is unrelated to file access controls.

Memory tip: Think "Endpoint = everything on the machine" - files, processes, ports, registry, and their attributes (like ACLs) all live in the Endpoint data model because they describe the state of a host system.

Topics

#CIM#Endpoint data model#file access controls#data normalization

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice