Exam SPLK-5001 Topic 3 Question 7 Discussion

Actual exam question for Splunk's SPLK-5001 exam
Question #: 7
Topic #: 3
An analyst investigates an IDS alert and confirms suspicious traffic to a known malicious IP. What Enterprise Security data model would they use to investigate which process initiated the network connection?

Suggested Answer: B Vote an answer

by Martin at Sep 13, 2026, 05:47 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10