Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?
The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?
When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?
An engineer adds a custom event status of ' Testing ' and accidentally makes it the new default status. Their SOC calculates some metrics based on Notable status change sequences, starting from the old default status of ' New ' . Which metrics can be affected by this mistake?
When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?
Which syntax is correct to create two new rows on an existing threat intelligence collection?
When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform creates its column stores?
An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?
Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
An engineer has discovered that an acquired company uses a duplicate IP address space. Which feature of the asset and identity framework could be turned on that would allow for the separation of company IP address ranges within a lookup?
An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?
Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?
Which of the following is a methodology to help prevent malicious lateral movement?
Risk scores are associated with how many levels of risk in Enterprise Security by default?
While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation that will check a potentially malicious URL against a remote URL filtering list. Which of the following options will work for them?
During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?
A Splunk administrator needs to integrate a third-party vulnerability management tool to automate remediation workflows. What is the most efficient first step?
What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?
Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)
An engineer receives a report that the “Traffic over time by action†dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they are CIM compliant. What other configuration may be missing?
Which of the following actions will allow access to a list of alert actions via the API?
How does Mission Control decipher which response template to assign to findings?
What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?
The SOC notices over the course of an investigation there are numerous logs similar to the following:
UDP: query: reallybad.c2.com IN A response: SERVFAIL
What detection should be created to alert on this behavior for the future?
When creating detections, which of the following sequences would result in the most performant SPL query?
What must be configured as a setting in a correlation search for a notable to be generated?