nerdexam
Splunk

SPLK-5002 · Question #53

In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?

The correct answer is B. file_intel. In Splunk Enterprise Security, the file_intel lookup is used for threat intelligence related to files, such as file hashes or suspicious file indicators. This lookup allows correlation searches and risk scoring to incorporate known malicious file information.

Threat Intelligence Integration

Question

In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?

Options

  • Afile_hash
  • Bfile_intel
  • Cuser_intel
  • Duser_hash

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    82% (27)
  • C
    3% (1)
  • D
    6% (2)

Explanation

In Splunk Enterprise Security, the file_intel lookup is used for threat intelligence related to files, such as file hashes or suspicious file indicators. This lookup allows correlation searches and risk scoring to incorporate known malicious file information.

Topics

#threat intelligence#file_intel#ES lookups#threat lookup tables

Community Discussion

No community discussion yet for this question.

Full SPLK-5002 Practice