Splunk
SPLK-5002 · Question #53
In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?
The correct answer is B. file_intel. In Splunk Enterprise Security, the file_intel lookup is used for threat intelligence related to files, such as file hashes or suspicious file indicators. This lookup allows correlation searches and risk scoring to incorporate known malicious file information.
Threat Intelligence Integration
Question
In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?
Options
- Afile_hash
- Bfile_intel
- Cuser_intel
- Duser_hash
How the community answered
(33 responses)- A9% (3)
- B82% (27)
- C3% (1)
- D6% (2)
Explanation
In Splunk Enterprise Security, the file_intel lookup is used for threat intelligence related to files, such as file hashes or suspicious file indicators. This lookup allows correlation searches and risk scoring to incorporate known malicious file information.
Topics
#threat intelligence#file_intel#ES lookups#threat lookup tables
Community Discussion
No community discussion yet for this question.