Splunk Flashcards

1
Q

What are the two main Splunk SIEM tool options?

A

Splunk® Enterprise and Splunk® Cloud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of Splunk tools in general?

A

To collect, search, monitor, and analyze log data from multiple sources to obtain full visibility into an organization’s everyday operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security posture dashboard (Splunk) - Purpose?

A

Displays the last 24 hours of an organization’s notable security-related events and trends; helps determine if security infrastructure and policies are performing as designed; allows real-time threat monitoring and investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Executive summary dashboard (Splunk) - Purpose?

A

Analyzes and monitors the overall health of the organization over time; helps improve security measures to reduce risk; provides high-level insights to stakeholders (e.g., summaries of incidents and trends).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Incident review dashboard (Splunk) - Purpose?

A

Allows analysts to identify suspicious patterns in the event of an incident; highlights higher-risk items needing immediate review; provides a visual timeline of events leading up to an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk analysis dashboard (Splunk) - Purpose?

A

Helps analysts identify risk for each risk object (user, computer, IP address); shows changes in risk-related activity or behavior (e.g., unusual login times, high network traffic); helps prioritize risk mitigation efforts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Chronicle?

A

A cloud-native SIEM tool from Google that retains, analyzes, and searches log data to identify potential security threats, risks, and vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does Chronicle allow you to collect and analyze log data?

A

According to a specific asset, a domain name, a user, or an IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Enterprise insights dashboard (Chronicle) - Purpose?

A

Highlights recent alerts; identifies suspicious domain names (IOCs) with confidence scores and severity levels; helps monitor activity related to critical assets (e.g., unusual logins).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data ingestion and health dashboard (Chronicle) - Purpose?

A

Shows the number of event logs, log sources, and success rates of data being processed into Chronicle; helps ensure correct log source configuration and error-free log reception.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

IOC matches dashboard (Chronicle) - Purpose?

A

Indicates the top threats, risks, and vulnerabilities; helps observe IOCs (domain names, IP addresses, devices) over time to identify trends and prioritize security efforts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Main dashboard (Chronicle) - Purpose?

A

Displays a high-level summary of data ingestion, alerting, and event activity over time; provides a timeline of security events (e.g., spikes in failed logins) to identify threat trends.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Rule detections dashboard (Chronicle) - Purpose?

A

Provides statistics related to incidents with the highest occurrences, severities, and detections over time; allows access to alerts triggered by specific detection rules (e.g., malicious attachments) to manage recurring incidents and establish mitigation tactics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

User sign in overview dashboard (Chronicle) - Purpose?

A

Provides information about user access behavior; allows access to all user sign-in events to identify unusual activity (e.g., simultaneous logins from multiple locations) and mitigate threats to user accounts and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Incident response:

A

An organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Log:

A

A record of events that occur within an organization’s systems

17
Q

Metrics:

A

ey technical attributes such as response time, availability, and failure rate, which are used to assess the performance of a software application

18
Q

Operating system (OS):

A

The interface between computer hardware and the user

19
Q

Playbook:

A

A manual that provides details about any operational action

20
Q

Security information and event management (SIEM)

A

An application that collects and analyzes log data to monitor critical activities in an organization

21
Q

Security orchestration, automation, and response (SOAR):

A

A collection of applications, tools, and workflows that use automation to respond to security events

22
Q

SIEM tools:

A

A software platform that collects, analyzes, and correlates security data from various sources across your IT infrastructure that helps identify and respond to security threats in real-time, investigate security incidents, and comply with security regulations

23
Q

Splunk Cloud:

A

A cloud-hosted tool used to collect, search, and monitor log data

24
Q

Splunk Enterprise:

A

A self-hosted tool used to retain, analyze, and search an organization’s log data to provide security information and alerts in real-time