WorksheetsTraditional SIEM VS Splunk For Security
Total questions: 10
Worksheet time: 5mins
3 Solutions of Security Operation Suite
Splunk ES
Splunk Infosec
Splunk UBA
Splunk Phantom
Bajak Laut dan Kapal Selam Pada Permasalahan Traditional SIEM diibaratkan sebagai apa?
APT
Phising
DDOS
Insider Attacs
Perbedaan pada Platform Splunk Enterprise dan Splunk Cloud adalah
Function
Reporting
Deployment
App
Solusi yang paling tepat untuk permasalahan Traditional SIEM terkait Insider Attack adalah
Splunk Infosec
Splunk Security Essential
Splunk UBA
Splunk Phantom
Sebutkan 3 Permasalahan Traditional SIEM
Know Normal, Find Evil
Many False Positives
New pattern of attacks didn’t trigger the rules
Bad Behaviour Internal Employee
Kegunaan Splunk UBA
A logical expression that causes the system to take a specific action if a particular event occurs
Detect unknown threats and anomalous user behavior using machine learning
Security use cases, including continuous monitoring and security investigations
security orchestration, automation and response (SOAR) platform
Usecase of Security Operation Suite
Security Monitoring
Outsider Threat Detection
Security Monitoring
SOC Automation
Free App on Splunk Base
Splunk UBA
Splunk Security Essential
Splunk Enterprise Security
Splunk Infosec
Sebutback Back Bone dari Splunk Cloud yang telah bekerja sama
Kegunaan Splunk Phantom
Security Monitoring
a site where users can post and share apps and add-ons
Detect unknown threats and anomalous user behavior using machine learning
Automation
