SPLK-5002 Exam Question 21
Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which Eventcode associated to PowerShell Script Block Logging would be used to detect this activity?
SPLK-5002 Exam Question 22
Which Splunk feature enables integration with third-party tools for automated response actions?
SPLK-5002 Exam Question 23
Which action improves the effectiveness of notable events in Enterprise Security?
SPLK-5002 Exam Question 24
Below is an example of a sysmon process create log. Which EventCode would be associated to this log entry?


SPLK-5002 Exam Question 25
Which features of Splunk are crucial for tuning correlation searches? (Choose three)
