An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
This is a tricky one. I'm not super familiar with the Splunk CIM, so I'm not sure which field would contain the attacker's IP address. I'll have to guess and hope for the best on this one.
Okay, let me think this through. The question is asking about lateral movement, so the IP address we're looking for would be the source IP, not the destination. I'm pretty confident the answer is C. src_nt_host.
Hmm, I'm a bit unsure about this one. I know the Splunk CIM documentation is important, but I can't quite remember the specific field names off the top of my head. I'll need to review the documentation carefully before answering.
This seems straightforward. The question is asking about the field that would contain the IP address of the host from which the attacker is moving, so I think the answer is D. src_ip.
Luis
4 months agoJulieta
5 months agoAlease
5 months agoNakita
5 months agoArlie
5 months agoDawne
5 months agoMaricela
6 months agoMauricio
6 months agoBurma
6 months agoShannon
6 months agoMarshall
6 months agoCassie
6 months agoCathern
6 months agoCoral
11 months agoLilli
11 months agoGerald
11 months agoFrederica
10 months agoAngelo
10 months agoRichelle
11 months agoLavina
11 months agoAnnamae
10 months agoGerman
11 months agoHannah
11 months agoGayla
1 year agoFranchesca
1 year agoGlory
11 months agoNa
11 months agoDonette
1 year agoGayla
1 year ago