Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75only

Splunk SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Exam Practice Test

Demo: 31 questions
Total 105 questions

Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Question 1

Which of the following can process data from configured containers using an automated sequence of actions?

Options:

A.

Cases

B.

Workbooks

C.

Containers

D.

Playbooks

Question 2

How can an engineer verify if results will return for a potential detection based on historical events within the organization?

Options:

A.

Run the detection with appropriate earliest and latest constraints covering the historical events.

B.

Run the detection against production data only within the default current time range.

C.

Run the detection using an inappropriate time constraint that does not cover the historical events.

D.

Run the detection in Splunk Attack Range against the latest Atomic Red Team injections.

Question 3

Which Enterprise Security components provide enrichment to the Risk Framework?

Options:

A.

Assets & Identities Framework, Risk Factoring, Annotations

B.

Risk Object, Notable Framework, Data Models

C.

Assets & Identities Framework, Threat Intelligence, Notes

D.

Risk Object, Threat Intelligence, Data Models

Question 4

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

Options:

A.

user_id

B.

user

C.

action

D.

identity

Question 5

An engineer creates a new event type. What defines the association of this event type to an applicable data model?

Options:

A.

The tag(s)

B.

The search string

C.

The field alias

D.

The saved search name

Question 6

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?

Options:

A.

Enterprise Security Content Update App

B.

Splunk Security Essentials App

C.

Enterprise Security

D.

Supporting add-on for MITRE ATT & CK

Question 7

Which of the following is a methodology to help prevent malicious lateral movement?

Options:

A.

Breakglass

B.

Lockheed Martin Cyber Kill Chain®

C.

MITRE ATT & CK®

D.

Zero Trust

Question 8

Which of the following identifies elements of the Detection Development Lifecycle (DDLC)?

Options:

A.

Research, Develop, Document, Test, Deploy

B.

Research, Design, Deploy, Validate

C.

Design, Develop, Deploy, Monitor, Maintain

D.

Design, Develop, Test, Deploy

Question 9

Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?

Options:

A.

Knowledge objects

B.

Commands

C.

Lookups

D.

Macros

Question 10

The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?

Options:

A.

MTTI

B.

MTBR

C.

MTTR

D.

MTTD

Question 11

Which tool can help provide a baseline of the data sources in a given Splunk environment?

Options:

A.

Enterprise Security Content Update

B.

Enterprise Security Data Library

C.

Splunk Security Essentials Analytic Stories

D.

Splunk Security Essentials Data Inventory

Question 12

What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?

Options:

A.

Aliases

B.

JSON

C.

Tokens

D.

Environment variables

Question 13

In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?

Options:

A.

A multiplier of risk that depends on the characteristics of the specific user or asset.

B.

An event that modifies risk based on the characteristics of the specific user or asset.

C.

A tool to enable risk data model acceleration.

D.

A SOAR action that is drawn from annotations.

Question 14

Which of the following is a reason to utilize ES risk framework as a part of detection building?

Options:

A.

Help accelerate the run time of detections, allowing a faster mean time to detection.

B.

Create a feedback loop into threat intelligence to identify potential insider threats.

C.

Help prioritize security findings based on their potential business impact.

D.

Simplify SOAR automation and remediation, lowering the mean time to recover.

Question 15

Which REST call will show a list of alerts with their specific commands, app, and title?

Options:

A.

| rest /servicesNS/admin/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

B.

| rest /servicesNS/user/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

C.

| rest /servicesNs/admin/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

D.

| rest /servicesNS/user/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

Question 16

When using SOAR to automate a response with a zero trust approach, which of the following represents a valid order of operations?

Options:

A.

Contain, triage initial incident, identify scope, remediate and/or restore

B.

Triage initial incident, identify scope, contain, remediate and/or restore

C.

Identify, scope, remediate and/or restore, triage

D.

Observe, orient, decide, act

Question 17

The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?

Options:

A.

Workbooks

B.

Events

C.

Cases

D.

Incidents

Question 18

Based on the provided screenshot, different machines or accounts have been associated with chosen threat objects. Which two Enterprise Security frameworks are responsible for programmatically associating this information?

Options:

A.

Threat Intelligence, Risk

B.

Risk, Assets & Identities

C.

Risk, Incident Review

D.

Threat Intelligence, Assets & Identities

Question 19

An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?

Options:

A.

Correlation search throttling

B.

Correlation search priority

C.

Adaptive risk modifier

D.

Adaptive response actions

Question 20

Which action improves the effectiveness of notable events in Enterprise Security?

Options:

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Question 21

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

Options:

A.

Search Splunk Enterprise Security for similar or duplicate events based on the threat_object field in a risk notable.

B.

Search Splunk Enterprise Security for all related events based on key fields in a notable and select how to process the results to decide which events to merge into the current investigation.

C.

Search Splunk Enterprise Security for similar or duplicate events based on the risk_object field in a risk notable.

D.

Search Splunk Enterprise Security for all related events based on key fields in a risk notable and select how to process the results to decide which events to merge into the current investigation.

Question 22

Which of the following is not a type of metadata that can be returned by the metadata command?

Options:

A.

hosts

B.

sources

C.

assets

D.

sourcetypes

Question 23

In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?

Options:

A.

GET

B.

POST

C.

STOR

D.

PUT

Question 24

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?

Options:

A.

Supporting add-on for MITRE ATT & CK

B.

Splunk Security Essentials App

C.

Enterprise Security

D.

Enterprise Security Content Update App

Question 25

The following SPL is designed to report on a certain SOC metric. Which metric is the most likely topic for this report?

| tstats summariesonly=true earliest(_time) as _time

FROM datamodel=Incident_Management

BY " Notable_Events.Meta.rule_id "

| rename " Notable_Events.Meta.* " as " * "

| lookup update=true incident_updates_lookup rule_id OUTPUTNEW time

| search time=*

| stats earliest(_time) as create_time, min(time) as triage_time by rule_id

| eval diff=triage_time-create_time,

stat_type=if(

create_time < relative_time(now(), " -7d@d " ),

" past " ,

" current "

),

past=if(stat_type= " past " , 1, 0),

current=if(stat_type= " current " , 1, 0),

past_diff=if(stat_type= " past " , diff, 0),

current_diff=if(stat_type= " current " , diff, 0)

| stats sum(past) AS past,

sum(current) AS current,

sum(past_diff) AS past_diff,

sum(current_diff) AS current_diff

| eval past=round(past_diff/past/60),

current=round(current_diff/current/60)

| table past, current

| transpose

Options:

A.

Mean time to Triage

B.

Mean time to Respond

C.

Mean time to Resolve

D.

Dwell Time

Question 26

What external support consideration should an engineer account for if they plan to automate the disabling of a system or user?

Options:

A.

Communicate the actions to the IT Help Desk.

B.

Enable logging on the playbook.

C.

Validate that the system or user is not already disabled.

D.

Add the " support " tag to the playbook.

Question 27

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

Options:

A.

Parameters

B.

Payload

C.

Headers

D.

KV Elements

Question 28

What framework in Enterprise Security allows engineers to build detections using known malicious IOCs, comparing them to event logs to find suspicious behavior?

Options:

A.

Asset & Intelligence Framework

B.

Incident Management Framework

C.

Threat Intelligence Framework

D.

OSINT Framework

Question 29

What is a key feature of effective security reports for stakeholders?

Options:

A.

High-level summaries with actionable insights

B.

Detailed event logs for every incident

C.

Exclusively technical details for IT teams

D.

Excluding compliance-related metrics

Question 30

Which field in the risk index is used to describe the activity within a finding?

Options:

A.

risk_message

B.

risk_description

C.

risk_object

D.

risk_reason

Question 31

What is Enterprise Security ' s default way of determining the urgency of a finding (notable event)?

Options:

A.

Multiply the risk score of a detection by how many times it has run.

B.

Leverage the scheduling priority of the detection to know what ' s most critical.

C.

Add risk scores for associated objects within a network.

D.

Take into account the priority assigned to the asset/identity as well as the severity value assigned to the finding.

Demo: 31 questions
Total 105 questions