SPLK-5001 · Question #31
The Security Operations Center (SOC) manager is interested in creating a new dashboard for typosquatting after a successful campaign against a group of senior executives. Which existing ES dashboard…
The correct answer is D. New Domain Analysis. New Domain Analysis is the correct starting point because typosquatting attacks rely on newly registered domains that closely mimic legitimate ones - detecting them requires monitoring recently created domains for suspicious similarities to known-good domains. The IAM Activity…
Question
The Security Operations Center (SOC) manager is interested in creating a new dashboard for typosquatting after a successful campaign against a group of senior executives. Which existing ES dashboard could be used as a starting point to create a custom dashboard?
Options
- AIAM Activity
- BMalware Center
- CAccess Anomalies
- DNew Domain Analysis
How the community answered
(55 responses)- A2% (1)
- B4% (2)
- C5% (3)
- D89% (49)
Explanation
New Domain Analysis is the correct starting point because typosquatting attacks rely on newly registered domains that closely mimic legitimate ones - detecting them requires monitoring recently created domains for suspicious similarities to known-good domains. The IAM Activity dashboard tracks identity and access management events like logins and privilege changes, which is unrelated to domain registration monitoring. Malware Center focuses on endpoint threats and malicious file/signature detection, not domain-name manipulation. Access Anomalies looks for unusual user behavior patterns and would only catch the downstream effect of a successful attack, not the typosquatted domain itself.
Memory tip: "Squatters register new property" - typosquatting is fundamentally about new malicious domains, so anchor it to the New Domain Analysis dashboard.
Topics
Community Discussion
No community discussion yet for this question.