// PATH EXAM

🎯 Detection Engineering

8 questions; you pass with 6. It is graded on the server and you will only see your score. If you pass, you can issue your certificate. Review the path first

1. What does PowerShell Event ID 4104 (Script Block Logging) record?
2. Which Event ID records a process creation (with auditing enabled)?
3. In KQL (Sentinel, Defender), which operator filters the rows that meet a condition?
4. What is Sigma?
5. And a failed logon?
6. What does Event ID 1102 in the Security log indicate?
7. "powershell -enc SQBFAFgA…": how is the argument encoded?
8. What is a false positive in a detection rule?