SIEM
/ /
Fundamentals Exam Questions With Correct Answers
/ // // // // //
GCP //logs //can //be //ingested //into //chronicle //using //what //method?
A.) //Forwarder //
B.) //Cloud
C.) //API
D.) //Direct //Ingestion //- //CORRECT //ANSWERS(S)✔✔D.) //Direct //Ingestion
What //search //component //is //used //for //threat //hunting //and //other //indepth //use //cases?
A.) //Investigative //Search
B.) //UDM //Search
C.) //Raw //Log //Search
D.) //None //of //the //above //- //CORRECT //ANSWERS(S)✔✔B.) //UDM //Search
What //information //do //you //need //to //store //after //creating //a //rule //with //the //detection //API?
A.) //Rule //ID //and //Rule //Version
B.) //Rule //name
C.) //Rule //author
D.) //Rule //conditions //- //CORRECT //ANSWERS(S)✔✔A.) //Rule //ID //and //Rule //Version
, What //language //are //Chronicle //parsers //based //on?
A.) //Python
B.) //HTML
C.) //Logstash
D.) //GoLang //- //CORRECT //ANSWERS(S)✔✔C.) //Logstash
On //premise //data //requires //the //use //of //a //__________ //to //collect //data?
A.) //Forwarder
B.) //Cloud-Cloud //Service
C.) //Ingestion //API
D.) //Direct //Ingestion //- //CORRECT //ANSWERS(S)✔✔A.) //Forwarder
Chronicle //dashboards //are //powered //by //Looker? //(T/F)
A.) //True
B.) //False //- //CORRECT //ANSWERS(S)✔✔A.) //True
Ingest //Health //is //found //in //which //Dashboard?
A.) //data //ingestion //and //health
B.) //IOC //Matches
C.) //Main
D.) //User //Sign //in //Overview //- //CORRECT //ANSWERS(S)✔✔A.) //data //ingestion //and //health