Splunk
SPLK-5002 · Question #115
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?
The correct answer is C. http_intel. A list of malicious domains (FQDNs) would be stored in the http_intel KV store within Splunk Enterprise Security. This KV store is specifically designed for HTTP-based threat intelligence indicators such as domains and URLs.
Threat Intelligence Integration
Question
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?
Options
- Acertificate_intel
- Bservice_intel
- Chttp_intel
- Dip_intel
How the community answered
(33 responses)- A12% (4)
- B3% (1)
- C79% (26)
- D6% (2)
Explanation
A list of malicious domains (FQDNs) would be stored in the http_intel KV store within Splunk Enterprise Security. This KV store is specifically designed for HTTP-based threat intelligence indicators such as domains and URLs.
Topics
#threat intelligence#KV store#FQDN#http_intel
Community Discussion
No community discussion yet for this question.