nerdexam
Splunk

SPLK-5001 · Question #93

A user reports to the Security Operations Center (SOC) that the following screen is displayed on their computer: Which of the following source types would be most useful for the SOC analyst to…

The correct answer is D. XmlWinEventLog. Windows Event Logs (XmlWinEventLog) will show process creation events, service installations, and other system activities - essential for tracing how the ransomware payload was delivered and executed on the host.

Incident Investigation and Response

Question

A user reports to the Security Operations Center (SOC) that the following screen is displayed on their computer:

Which of the following source types would be most useful for the SOC analyst to determine how this occurred?

Exhibit

SPLK-5001 question #93 exhibit

Options

  • Alog4j
  • Blog4j
  • Caccess_combined
  • DXmlWinEventLog

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    12% (3)
  • C
    12% (3)
  • D
    73% (19)

Explanation

Windows Event Logs (XmlWinEventLog) will show process creation events, service installations, and other system activities - essential for tracing how the ransomware payload was delivered and executed on the host.

Topics

#Windows Event Log#endpoint security#ransomware#source types

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice