An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
This is a tricky one. I'm not super familiar with the Splunk CIM, so I'm not sure which field would contain the attacker's IP address. I'll have to guess and hope for the best on this one.
Okay, let me think this through. The question is asking about lateral movement, so the IP address we're looking for would be the source IP, not the destination. I'm pretty confident the answer is C. src_nt_host.
Hmm, I'm a bit unsure about this one. I know the Splunk CIM documentation is important, but I can't quite remember the specific field names off the top of my head. I'll need to review the documentation carefully before answering.
This seems straightforward. The question is asking about the field that would contain the IP address of the host from which the attacker is moving, so I think the answer is D. src_ip.
Luis
3 months agoJulieta
3 months agoAlease
3 months agoNakita
4 months agoArlie
4 months agoDawne
4 months agoMaricela
4 months agoMauricio
4 months agoBurma
5 months agoShannon
5 months agoMarshall
5 months agoCassie
5 months agoCathern
5 months agoCoral
10 months agoLilli
10 months agoGerald
10 months agoFrederica
9 months agoAngelo
9 months agoRichelle
9 months agoLavina
10 months agoAnnamae
9 months agoGerman
9 months agoHannah
10 months agoGayla
11 months agoFranchesca
11 months agoGlory
10 months agoNa
10 months agoDonette
11 months agoGayla
11 months ago