An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
This is a tricky one. I'm not super familiar with the Splunk CIM, so I'm not sure which field would contain the attacker's IP address. I'll have to guess and hope for the best on this one.
Okay, let me think this through. The question is asking about lateral movement, so the IP address we're looking for would be the source IP, not the destination. I'm pretty confident the answer is C. src_nt_host.
Hmm, I'm a bit unsure about this one. I know the Splunk CIM documentation is important, but I can't quite remember the specific field names off the top of my head. I'll need to review the documentation carefully before answering.
This seems straightforward. The question is asking about the field that would contain the IP address of the host from which the attacker is moving, so I think the answer is D. src_ip.
Luis
6 months agoJulieta
6 months agoAlease
6 months agoNakita
7 months agoArlie
7 months agoDawne
7 months agoMaricela
7 months agoMauricio
7 months agoBurma
8 months agoShannon
8 months agoMarshall
8 months agoCassie
8 months agoCathern
8 months agoCoral
1 year agoLilli
1 year agoGerald
1 year agoFrederica
12 months agoAngelo
12 months agoRichelle
1 year agoLavina
1 year agoAnnamae
12 months agoGerman
1 year agoHannah
1 year agoGayla
1 year agoFranchesca
1 year agoGlory
1 year agoNa
1 year agoDonette
1 year agoGayla
1 year ago