nerdexam
Splunk

SPLK-5001 · Question #99

A threat hunter creates a model of normal, expected activity on a portion of their network. Later, they compare observed activity against this model, looking for significant deviations. What is…

The correct answer is D. A baseline. In threat hunting, a “baseline” refers to a model of normal activity against which you compare current observations to identify significant deviations.

Threat Detection and Alerting

Question

A threat hunter creates a model of normal, expected activity on a portion of their network. Later, they compare observed activity against this model, looking for significant deviations. What is another name for this model?

Options

  • AA cluster.
  • BA time series.
  • CA data model.
  • DA baseline.

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    6% (2)
  • D
    88% (29)

Explanation

In threat hunting, a “baseline” refers to a model of normal activity against which you compare current observations to identify significant deviations.

Topics

#threat hunting#baseline#anomaly detection#behavioral modeling

Community Discussion

No community discussion yet for this question.

Full SPLK-5001 Practice