nerdexam
Splunk

SPLK-5001 · Question #29

A threat hunter generates a report containing the list of users who have logged in to a particular database during the last 6 months, along with the number of times they have each authenticated. They

Sign in or unlock SPLK-5001 to reveal the answer and full explanation for question #29. The question stem and answer options stay visible for context.

Threat Detection and Alerting

Question

A threat hunter generates a report containing the list of users who have logged in to a particular database during the last 6 months, along with the number of times they have each authenticated. They sort this list and remove any user names who have logged in more than 6 times. The remaining names represent the users who rarely log in, as their activity is more suspicious. The hunter examines each of these rare logins in detail. This is an example of what type of threat-hunting technique?

Options

  • ALeast Frequency of Occurrence Analysis
  • BCo-Occurrence Analysis
  • CTime Series Analysis
  • DOutlier Frequency Analysis

Unlock SPLK-5001 to see the answer

You've previewed enough free SPLK-5001 questions. Unlock SPLK-5001 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#threat hunting#Least Frequency of Occurrence#authentication analysis#outlier detection
Full SPLK-5001 Practice