ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 3 - SPLK-5001 discussion

Report
Export

An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?

A.
host
Answers
A.
host
B.
dest
Answers
B.
dest
C.
src_nt_host
Answers
C.
src_nt_host
D.
src_ip
Answers
D.
src_ip
Suggested answer: D
asked 23/09/2024
Thanh Tran
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first