nerdexam
Splunk

SPLK-5002 · Question #117

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk's method…

The correct answer is A. Analytic Stories. Splunk uses Analytic Stories to group related detections together that align with a specific threat scenario, such as ransomware. These stories provide a collection of correlation searches, baselines, and contextual guidance to detect, investigate, and respond to adversary…

Advanced Threat Hunting and Analytics

Question

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk's method for grouping these types of detections together?

Options

  • AAnalytic Stories
  • BData models
  • CThreat Intelligence
  • DAssets & Identities framework

How the community answered

(26 responses)
  • A
    69% (18)
  • B
    4% (1)
  • C
    12% (3)
  • D
    15% (4)

Explanation

Splunk uses Analytic Stories to group related detections together that align with a specific threat scenario, such as ransomware. These stories provide a collection of correlation searches, baselines, and contextual guidance to detect, investigate, and respond to adversary behaviors. Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.

Topics

#Analytic Stories#ransomware detection#detection grouping#threat correlation

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice