Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Splunk SPLK-5002 Dumps Questions Answers

Page: 1 / 8
Total 105 questions

Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Question 1

When using SOAR to automate a response with a zero trust approach, which of the following represents a valid order of operations?

Options:

A.

Contain, triage initial incident, identify scope, remediate and/or restore

B.

Triage initial incident, identify scope, contain, remediate and/or restore

C.

Identify, scope, remediate and/or restore, triage

D.

Observe, orient, decide, act

Buy Now
Question 2

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?

Options:

A.

Enterprise Security Content Update App

B.

Splunk Security Essentials App

C.

Enterprise Security

D.

Supporting add-on for MITRE ATT & CK

Question 3

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

Options:

A.

Status, Owner

B.

Urgency, Status

C.

Severity, Owner

D.

User, Status

Question 4

Which fields are used to determine asset priority, when priority is assigned through an asset and identity lookup?

Options:

A.

dest, src, or dvc

B.

dest, src, or tag

C.

user or src_user

D.

dest_user or src_user

Question 5

In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?

Options:

A.

GET

B.

POST

C.

STOR

D.

PUT

Question 6

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:

A.

This a Key Result Indicator, not a KPI. It is a metric that is measuring the results of the perimeter firewall ' s actions, not the performance of the firewall.

B.

Perimeter firewalls are exposed on the internet directly and thus subject to automated scanners and attack tools.

C.

The metric is too high level, it should be broken down by the type of block. For example, blocks of remote systems that have repeated failed connections to services that do not exist.

D.

Perimeter firewalls should be measured on both the number of connections that they permit as well as the number they block.

Question 7

How can an engineer verify if results will return for a potential detection based on historical events within the organization?

Options:

A.

Run the detection with appropriate earliest and latest constraints covering the historical events.

B.

Run the detection against production data only within the default current time range.

C.

Run the detection using an inappropriate time constraint that does not cover the historical events.

D.

Run the detection in Splunk Attack Range against the latest Atomic Red Team injections.

Question 8

How does Mission Control decipher which response template to assign to findings?

Options:

A.

This is determined when creating a detection in ES, which gets carried over to Mission Control.

B.

Mission Control uses AI to decipher which response templates are assigned.

C.

Response templates are assigned to specific incident types.

D.

The only way to configure this is with SOAR.

Question 9

An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?

Options:

A.

The endpoint that the asset is configured for does not exist.

B.

Either the asset username or password is incorrect.

C.

The asset endpoint requires a token rather than a username and password.

D.

Asset credentials do not have adequate permissions.

Question 10

Based on this example image, if it is detected that a member has been added to a security-enabled local group, how many risk events will be created?

Options:

A.

20

B.

1

C.

10

D.

2

Question 11

Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?

Options:

A.

Knowledge objects

B.

Commands

C.

Lookups

D.

Macros

Question 12

Consider the following series of events:

4:00 GMT Detection runs for interval 3:30–4:00

4:30 GMT Detection runs for interval 4:00–4:30

4:35 GMT Event 1 occurs on an endpoint

4:45 GMT Event 1 is indexed

5:00 GMT Detection runs for interval 4:30–5:00

5:05 GMT Event 1 finding is added to ES with timestamp 4:35

5:24 GMT Event 2 occurs on an endpoint

5:30 GMT Detection runs for interval 5:00–5:30

5:35 GMT Event 2 is indexed

6:00 GMT Detection runs for interval 5:30–6:00

What is the problem with the detection schedule chosen and how can it be solved?

Options:

A.

The logs are delayed so the detection time window needs to be decreased.

B.

The time window for the detection is too small, causing duplicate alerts.

C.

The time window for the detection is too large, causing duplicate alerts.

D.

The logs are delayed so the detection time window needs to be increased.

Question 13

MITRE D3FEND is designed to compliment MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?

Options:

A.

Harden, Detect, Exclude, Deceive, Eradicate

B.

Harden, Detect, Isolate, Disrupt, Evict

C.

Harden, Detect, Exclude, Define, Eradicate

D.

Harden, Detect, Isolate, Deceive, Evict

Question 14

What is the primary purpose of data indexing in Splunk?

Options:

A.

To ensure data normalization

B.

To store raw data and enable fast search capabilities

C.

To secure data from unauthorized access

D.

To visualize data using dashboards

Question 15

Which field in the risk index is used to describe the activity within a finding?

Options:

A.

risk_message

B.

risk_description

C.

risk_object

D.

risk_reason

Question 16

For detections that leverage a CIM data model, which aspect of the configuration is responsible for determining which indexes are being searched?

Options:

A.

The data model ' s constraint macro.

B.

The data model ' s index list.

C.

The data model ' s root expression.

D.

The data model ' s dataset hierarchy.

Question 17

When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?

Options:

A.

Input

B.

Automation

C.

Process

D.

Response

Question 18

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

Options:

A.

Search Splunk Enterprise Security for similar or duplicate events based on the threat_object field in a risk notable.

B.

Search Splunk Enterprise Security for all related events based on key fields in a notable and select how to process the results to decide which events to merge into the current investigation.

C.

Search Splunk Enterprise Security for similar or duplicate events based on the risk_object field in a risk notable.

D.

Search Splunk Enterprise Security for all related events based on key fields in a risk notable and select how to process the results to decide which events to merge into the current investigation.

Question 19

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:

A.

Perimeter firewalls should be measured on both the number of connections they permit and the number they block.

B.

Perimeter firewalls are exposed to the Internet and therefore subject to automated scanners and attack tools.

C.

The metric is too high level and should instead be broken down by the type of block.

D.

This is a Key Result Indicator, not a KPI; it measures the results of the perimeter firewall ' s actions rather than the performance of the firewall.

Question 20

Which action improves the effectiveness of notable events in Enterprise Security?

Options:

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Question 21

Once an engineer has determined that a new detection will fire, what is the next priority for that detection?

Options:

A.

Ensure that threat intelligence has been integrated for use with the detection.

B.

Ensure that all annotations, such as MITRE ATT & CK, are attached and understood with the detection.

C.

Ensure that the SOAR playbooks are available to automate the outcomes from the detection.

D.

Ensure that all fields that an analyst would need are present in the output from the detection.

Question 22

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

Options:

A.

A hierarchical organization chart

B.

Infrastructure architecture diagrams

C.

Application architecture diagrams

D.

Business Continuity or Disaster Recovery plan

Question 23

Which search command was used to generate the result in the image below?

Options:

A.

metadata

B.

datatype

C.

cim

D.

datamodel

Question 24

Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?

Options:

A.

TA-ThreatIntel

B.

ESS-Intel

C.

SA-ThreatIntelligence

D.

SA-ESSIntel

Question 25

Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?

Options:

A.

orig_sid

B.

risk_sid

C.

search_sid

D.

result_sid

Question 26

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

Options:

A.

Parameters

B.

Payload

C.

Headers

D.

KV Elements

Question 27

In the context of Splunk ' s Common Information Model (CIM), which construct ensures that events from different data sources appear in the applicable data model?

Options:

A.

Hosts

B.

Tags

C.

Assets

D.

Field names

Question 28

An engineer receives a report that the “Traffic over time by action” dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they are CIM compliant. What other configuration may be missing?

Options:

A.

The Network Sessions data model should be accelerated.

B.

The Performance data model is missing the network dataset.

C.

The Network Traffic data model should be accelerated.

D.

The Network Sessions data model has been deleted.

Question 29

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

Options:

A.

A raw-event search followed by aggregation.

B.

A non-index-grouped metadata search.

C.

An index=* event search followed by stats.

D.

A tstats search returning sourcetypes and grouping them by index.

Question 30

When building detections using the Authentication Data Model, which values are recommended for use against the action field?

Options:

A.

allowed, blocked, processing, error

B.

success, failure, pending, error

C.

allowed, blocked, inactivity, error

D.

success, denied, pending, error

Question 31

What field is used by default to direct data into CIM data model datasets?

Options:

A.

tag

B.

sourcetype

C.

source

D.

dataset

Page: 1 / 8
Total 105 questions