Threat Hunting and Remediation
SPLK-5001 · 30 questions
- Water-plant hunt finds no known malware hashes on jump hosts, and the hypothesis is that someone disabled logging or added a local admin. Which hunting technique is this?
- County SOC wants to hunt clerk VPN days that do not look like a normal 9-to-5 workweek. Which technique fits?
- The state ISAC publishes a C2 domain tied to a campaign against municipal email. What hunting technique should the city SOC run first against Web, DNS, and firewall data?
- An elections clerk identity that never touched the elections file server suddenly accessed it and then created a mailbox forwarding rule. Which hunt technique describes that sequence?
- City SOC has three open hunts: an unknown actor on the assessor network, a known campaign with ISAC IoCs, and a question of whether someone turned off Sysmon on a jump host. How should the analyst match techniques?
- County Asset and Identity records mark wastewater jump hosts as shouldupdate, but endpoint telemetry has not reported a patch cycle in 45 days. What hunt technique should the civic SOC apply first?
- Anomaly modeling flags a twenty-times spike in city website bandwidth every election night and during council livestreams. What should the hunter add to the model?
- A behavioral hunt finds several odd but individually weak actions on a permitting clerk identity. How should those findings feed Enterprise Security?
- The city proxy shows millions of visits to common sites and a handful of one-hit destination domains. What does long-tail analysis tell the hunter to inspect first?
- A hunter ranks municipal users by destination-port frequency and finds one clerk with a single connection to destport 4444. What long-tail approach does this illustrate?
- Failed logons against a county domain controller jump to three standard deviations above that DC's own baseline, and no threat-intel hash is present. What technique is the hunter using?
- A wastewater historian host writes ten times its normal volume to disk, but no known malware hash is present. What should the civic SOC do?
- The city SOC wants to hunt whether a valid finance account will create an inbox forwarding rule and then exfiltrate via personal cloud. What is the correct hypothesis-hunting sequence in Splunk?
- A junior hunter proposes the hypothesis that hackers are here on the elections network. What change makes it a testable Splunk hunt hypothesis?
- A hunt for new forwarding rules on city finance mailboxes returns no matches this week. What should the analyst do with that outcome?
- A hunt confirms rare destport 4444 egress from library kiosks. How should the civic SOC turn that success into continuous monitoring?
- Which Adaptive Response usage is appropriate for the city SOC?
- An analyst opens a notable for a parks workstation and wants Adaptive Response during the analyze stage. Which ad-hoc use is appropriate first?
- The same pair of actions—create a notable and add risk—should fire every time a parking-garage camera detection matches. How should Adaptive Response be configured?
- A hunter needs each true match on a court-clerk detection to raise the identity's risk score without paging email. Which default-style Adaptive Response should be selected?
- A correlation search emails the on-call analyst for every parking-meter result, and 5,000 meters flap overnight. What Adaptive Response configuration change is needed?
- On a fire-station notable, the Adaptive Response icon never shows success. What should the analyst check first?
- A notable fires on the city's 911 CAD server. Why is automatic isolation Adaptive Response usually the wrong next step?
- A new analyst asks what a SOAR playbook is in the city's defense stack. What is the accurate description?
- How can a scheduled detection automatically start SOAR work from Enterprise Security?
- A county analyst wants a playbook to run for one parks notable without changing the correlation search. What Enterprise Security trigger path should they use?
- While working an elections investigation in Enterprise Security, the analyst needs to launch playbook actions as part of the case workflow. Which trigger path does this describe?
- Leadership asks the civic SOC analyst to write the Python for a new SOAR playbook after a library kiosk incident. What is in scope for the Cybersecurity Defense Analyst?
- Which SOAR trigger policy fits the city's risk tolerance?
- A true-positive notable never appears in Splunk SOAR. Where should the civic SOC troubleshoot first?