Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Changed SPLK-5002 Exam Questions

Page: 5 / 8
Total 105 questions

Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Question 17

When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?

Options:

A.

Input

B.

Automation

C.

Process

D.

Response

Question 18

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

Options:

A.

Search Splunk Enterprise Security for similar or duplicate events based on the threat_object field in a risk notable.

B.

Search Splunk Enterprise Security for all related events based on key fields in a notable and select how to process the results to decide which events to merge into the current investigation.

C.

Search Splunk Enterprise Security for similar or duplicate events based on the risk_object field in a risk notable.

D.

Search Splunk Enterprise Security for all related events based on key fields in a risk notable and select how to process the results to decide which events to merge into the current investigation.

Question 19

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:

A.

Perimeter firewalls should be measured on both the number of connections they permit and the number they block.

B.

Perimeter firewalls are exposed to the Internet and therefore subject to automated scanners and attack tools.

C.

The metric is too high level and should instead be broken down by the type of block.

D.

This is a Key Result Indicator, not a KPI; it measures the results of the perimeter firewall ' s actions rather than the performance of the firewall.

Question 20

Which action improves the effectiveness of notable events in Enterprise Security?

Options:

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Page: 5 / 8
Total 105 questions