Splunk
SPLK-5001 · Question #99
A threat hunter creates a model of normal, expected activity on a portion of their network. Later, they compare observed activity against this model, looking for significant deviations. What is…
The correct answer is D. A baseline. In threat hunting, a “baseline” refers to a model of normal activity against which you compare current observations to identify significant deviations.
Threat Detection and Alerting
Question
A threat hunter creates a model of normal, expected activity on a portion of their network. Later, they compare observed activity against this model, looking for significant deviations. What is another name for this model?
Options
- AA cluster.
- BA time series.
- CA data model.
- DA baseline.
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (29)
Explanation
In threat hunting, a “baseline” refers to a model of normal activity against which you compare current observations to identify significant deviations.
Topics
#threat hunting#baseline#anomaly detection#behavioral modeling
Community Discussion
No community discussion yet for this question.