nerdexam
Splunk

SPLK-5002 · Question #115

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

The correct answer is C. http_intel. A list of malicious domains (FQDNs) would be stored in the http_intel KV store within Splunk Enterprise Security. This KV store is specifically designed for HTTP-based threat intelligence indicators such as domains and URLs.

Threat Intelligence Integration

Question

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

Options

  • Acertificate_intel
  • Bservice_intel
  • Chttp_intel
  • Dip_intel

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    3% (1)
  • C
    79% (26)
  • D
    6% (2)

Explanation

A list of malicious domains (FQDNs) would be stored in the http_intel KV store within Splunk Enterprise Security. This KV store is specifically designed for HTTP-based threat intelligence indicators such as domains and URLs.

Topics

#threat intelligence#KV store#FQDN#http_intel

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice