Housing-authority SOC is investigating suspected ransomware on file servers. How should the analyst use a Splunk Lantern ransomware-investigation article?
Select an answer to reveal the explanation.
Short Explanation
Lantern's ransomware articles are a checklist: shadow copies deleted, unusual SMB, and the searches that test those questions. Use that structure on housing-authority servers. It is not a dump of exam stems and it is not sample data to inject.
Full Explanation
Splunk Lantern ransomware-investigation guides list the questions an analyst should ask and the example searches that support them, such as volume-shadow deletion and unusual SMB. A civic IR team applies that structure to local file-server telemetry and adapts the SPL; it does not treat Lantern as exam brain-dump material or load sample events into production. Waiting solely for a hash ignores the article's point: hunt the behaviors the guide already names.