Questions
As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:
- External host alerts can be collected from where?
a. Osquery
b. Zeek
c. Suricata
d. Filebeat
- External network alerts can be collected from where?
a. Osquery
b. Zeek
c. Tanium
d. Filebeat
- Indicator match rules can be fed from what module?
a. Filebeat System Module
b. Packetbeat
c. Auditbeat
d. Filebeat Threat Intel Module
- Which of the following query languages can timelines use for correlations?
a. KQL
b. SQL
c. EQL
d. Lucene
- What is the name of the tool that allows you to visually explore alerts?
a. Resolver
b. Hosts
c. Network
d. Timelines