Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Last Attempt SPLK-5002 Questions

Page: 8 / 8
Total 105 questions

Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Question 29

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

Options:

A.

A raw-event search followed by aggregation.

B.

A non-index-grouped metadata search.

C.

An index=* event search followed by stats.

D.

A tstats search returning sourcetypes and grouping them by index.

Question 30

When building detections using the Authentication Data Model, which values are recommended for use against the action field?

Options:

A.

allowed, blocked, processing, error

B.

success, failure, pending, error

C.

allowed, blocked, inactivity, error

D.

success, denied, pending, error

Question 31

What field is used by default to direct data into CIM data model datasets?

Options:

A.

tag

B.

sourcetype

C.

source

D.

dataset

Page: 8 / 8
Total 105 questions