Skip to content
CAS-005
Security Operations
medium
Question 8 of 22

A threat hunter is searching for signs of command-and-control traffic in network logs. The hunter needs to write a detection rule that can be used across multiple SIEM platforms. Which rule format is MOST appropriate?

AYARA
BSnort
CSigma
DSTIX

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion