Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Splunk > Cybersecurity Defense Analyst > SPLK-5002

SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Question and Answers

Question # 4

Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?

A.

orig_sid

B.

risk_sid

C.

search_sid

D.

result_sid

Full Access
Question # 5

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

A.

service_intel

B.

http_intel

C.

certificate_intel

D.

ip_intel

Full Access
Question # 6

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

A.

Status, Owner

B.

Urgency, Status

C.

Severity, Owner

D.

User, Status

Full Access
Question # 7

When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?

A.

Include the standard CIM fields for assets and identities in the detection output.

B.

Use an identity lookup to return all available identity information in the detection output.

C.

Use an asset lookup to return all available asset information in the detection output.

D.

Call an Active Directory adaptive response action to perform a real-time update.

Full Access
Question # 8

An engineer adds a custom event status of ' Testing ' and accidentally makes it the new default status. Their SOC calculates some metrics based on Notable status change sequences, starting from the old default status of ' New ' . Which metrics can be affected by this mistake?

A.

Mean Time to Respond, Mean Time to Resolve

B.

No metrics are impacted

C.

Mean Time to Triage, Dwell Time

D.

Mean Time to Resolve, Dwell Time

Full Access
Question # 9

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

A.

This a Key Result Indicator, not a KPI. It is a metric that is measuring the results of the perimeter firewall ' s actions, not the performance of the firewall.

B.

Perimeter firewalls are exposed on the internet directly and thus subject to automated scanners and attack tools.

C.

The metric is too high level, it should be broken down by the type of block. For example, blocks of remote systems that have repeated failed connections to services that do not exist.

D.

Perimeter firewalls should be measured on both the number of connections that they permit as well as the number they block.

Full Access
Question # 10

Which syntax is correct to create two new rows on an existing threat intelligence collection?

A.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] ' -G -X

B.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] '

C.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= " [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] "

D.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] ' -G -X

Full Access
Question # 11

When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform creates its column stores?

A.

Max summarization search time

B.

Backfill range

C.

Accelerate until maximum time

D.

Summary range

Full Access
Question # 12

An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?

A.

Correlation search throttling

B.

Correlation search priority

C.

Adaptive risk modifier

D.

Adaptive response actions

Full Access
Question # 13

Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?

A.

Detect Excessive AWS Security Scanning

B.

Detect Excessive User Account Lockouts

C.

Detect Excessive User Logins

D.

Detect Excessive Network Connections

Full Access
Question # 14

An engineer has discovered that an acquired company uses a duplicate IP address space. Which feature of the asset and identity framework could be turned on that would allow for the separation of company IP address ranges within a lookup?

A.

Entity Definitions

B.

Asset Classes

C.

Entity Zones

D.

Asset Annotations

Full Access
Question # 15

An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?

A.

The endpoint that the asset is configured for does not exist.

B.

Either the asset username or password is incorrect.

C.

The asset endpoint requires a token rather than a username and password.

D.

Asset credentials do not have adequate permissions.

Full Access
Question # 16

When should a detection be reviewed or retuned after deployment?

A.

Every 30 days.

B.

Only if it has generated a large amount of false positives.

C.

As defined by the established detection lifecycle.

D.

Only if it hasn ' t generated a finding after several weeks.

Full Access
Question # 17

Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?

A.

Risk Category

B.

Risk Rule

C.

Risk Incident Rule

D.

Risk Incident Notable

Full Access
Question # 18

Which of the following is a methodology to help prevent malicious lateral movement?

A.

Breakglass

B.

Lockheed Martin Cyber Kill Chain®

C.

MITRE ATT & CK®

D.

Zero Trust

Full Access
Question # 19

Risk scores are associated with how many levels of risk in Enterprise Security by default?

A.

(4) Info, Medium, High, Critical

B.

(3) Low, Medium, High

C.

(5) Info, Low, Medium, High, Critical

D.

(6) Info, Low, Medium, High, Critical, Unknown

Full Access
Question # 20

While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation that will check a potentially malicious URL against a remote URL filtering list. Which of the following options will work for them?

A.

Neither Adaptive Action or Input Playbook

B.

Adaptive Response Action or Input Playbook

C.

Adaptive Response Action

D.

Input Playbook

Full Access
Question # 21

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?

A.

Threat Intelligence

B.

Data models

C.

Analytic Stories

D.

Assets & Identities framework

Full Access
Question # 22

A Splunk administrator needs to integrate a third-party vulnerability management tool to automate remediation workflows. What is the most efficient first step?

A.

Set up a manual alerting system for vulnerabilities

B.

Use REST APIs to integrate the third-party tool with Splunk SOAR

C.

Write a correlation search for each vulnerability type

D.

Configure custom dashboards to monitor vulnerabilities

Full Access
Question # 23

What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?

A.

Aliases

B.

JSON

C.

Tokens

D.

Environment variables

Full Access
Question # 24

Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)

A.

Regular updates based on feedback

B.

Focusing solely on high-risk scenarios

C.

Collaborating with cross-functional teams

D.

Including detailed step-by-step instructions

E.

Excluding historical incident data

Full Access
Question # 25

An engineer receives a report that the “Traffic over time by action” dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they are CIM compliant. What other configuration may be missing?

A.

The Network Sessions data model should be accelerated.

B.

The Performance data model is missing the network dataset.

C.

The Network Traffic data model should be accelerated.

D.

The Network Sessions data model has been deleted.

Full Access
Question # 26

Which of the following actions will allow access to a list of alert actions via the API?

A.

| rest /services/alerts/adaptive_response_action

B.

| rest /services/alerts/correlationsearches

C.

| rest /services/alerts/alert actions/_acl

D.

| rest /services/alerts/alert_actions

Full Access
Question # 27

How does Mission Control decipher which response template to assign to findings?

A.

This is determined when creating a detection in ES, which gets carried over to Mission Control.

B.

Mission Control uses AI to decipher which response templates are assigned.

C.

Response templates are assigned to specific incident types.

D.

The only way to configure this is with SOAR.

Full Access
Question # 28

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

A.

A hierarchical organization chart

B.

Infrastructure architecture diagrams

C.

Application architecture diagrams

D.

Business Continuity or Disaster Recovery plan

Full Access
Question # 29

The SOC notices over the course of an investigation there are numerous logs similar to the following:

UDP: query: reallybad.c2.com IN A response: SERVFAIL

What detection should be created to alert on this behavior for the future?

A.

Excessive DNS Failures

B.

Excessive Authentication Failures

C.

Excessive Network Failures

D.

Excessive Endpoint Failures

Full Access
Question # 30

When creating detections, which of the following sequences would result in the most performant SPL query?

A.

Define base query, combine/summarize data, minimize data, execute calculations, format the data

B.

Define base query, minimize data, combine/summarize data, execute calculations, format the data

C.

Define base query, minimize data, combine/summarize data, format the data, execute calculations

D.

Define base query, minimize data, format the data, combine/summarize data, execute calculations

Full Access
Question # 31

What must be configured as a setting in a correlation search for a notable to be generated?

A.

A SOAR playbook must execute against the notable.

B.

Nothing; the correlation search will generate a notable automatically as an outcome.

C.

An Adaptive Response Action must be configured to enable the notable generation.

D.

The search must end with a | notable SPL command.

Full Access