Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 26 Topic 3 Discussion

Splunk Certified Cybersecurity Defense Engineer SPLK-5002 Question # 26 Topic 3 Discussion

SPLK-5002 Exam Topic 3 Question 26 Discussion:
Question #: 26
Topic #: 3

Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which EventCode associated to PowerShell Script Block Logging would be used to detect this activity?


A.

EventCode=4126


B.

EventCode=4168


C.

EventCode=4624


D.

EventCode=4104


Get Premium SPLK-5002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.