Splunk Observability Cloud Certified Metrics User — Question 45
The Security Operations Center (SOC) manager is interested in creating a new dashboard for typosquatting after a successful campaign against a group of senior executives. Which existing ES dashboard could be used as a starting point to create a custom dashboard?
Answer options
- A. IAM Activity
- B. Malware Center
- C. Access Anomalies
- D. New Domain Analysis
Correct answer: D
Explanation
The correct answer is D, New Domain Analysis, as it is specifically designed to analyze new domain registrations, which is closely related to typosquatting. The other options, while relevant to security monitoring, do not align as directly with the specific focus on domain analysis required for addressing typosquatting.