Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Cybersecurity Defense Analyst SPLK-5002 Book

Page: 6 / 8
Total 105 questions

Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Question 21

Once an engineer has determined that a new detection will fire, what is the next priority for that detection?

Options:

A.

Ensure that threat intelligence has been integrated for use with the detection.

B.

Ensure that all annotations, such as MITRE ATT & CK, are attached and understood with the detection.

C.

Ensure that the SOAR playbooks are available to automate the outcomes from the detection.

D.

Ensure that all fields that an analyst would need are present in the output from the detection.

Question 22

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

Options:

A.

A hierarchical organization chart

B.

Infrastructure architecture diagrams

C.

Application architecture diagrams

D.

Business Continuity or Disaster Recovery plan

Question 23

Which search command was used to generate the result in the image below?

Options:

A.

metadata

B.

datatype

C.

cim

D.

datamodel

Question 24

Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?

Options:

A.

TA-ThreatIntel

B.

ESS-Intel

C.

SA-ThreatIntelligence

D.

SA-ESSIntel

Page: 6 / 8
Total 105 questions