Lab S01 — Knowledge Check

10 questions  ·  Select all that apply where indicated  ·  Submit when ready to see your results

Question 1
Sysmon is only for Windows.
Question 2
Sysmon tracks which of the following?
Select all that apply
Question 3
Sysmon debuted in which year?
Question 4
What user account does the Splunk Universal Forwarder run as on Windows 10?
Question 5
Lusrmgr is a native Windows management program.
Question 6
What Windows group does the Splunk Forwarder need membership in to read and forward Sysmon logs?
Question 7
Why is adding "Everyone" to the Event Log Readers group a problem?
Question 8
What Microsoft software suite is Sysmon part of?
Question 9
What format are Sysmon logs forwarded in when using the renderXml = true setting?
Question 10
What language is used in Splunk Search & Reporting to query indexed data?
Back to Lab

Scroll up to review your answers and explanations.