Exam SPLK-5001 Topic 3 Question 7 Discussion
Actual exam question for Splunk's SPLK-5001 exam
Question #: 7
Topic #: 3
Question #: 7
Topic #: 3
An analyst investigates an IDS alert and confirms suspicious traffic to a known malicious IP. What Enterprise Security data model would they use to investigate which process initiated the network connection?
Suggested Answer: B Vote an answer
by Martin at Sep 13, 2026, 05:47 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).