Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Splunk Cybersecurity Defense Analyst SPLK-5002 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SPLK-5002 Premium Access

View all detail and faqs for the SPLK-5002 exam


762 Students Passed

84% Average Score

94% Same Questions
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

An engineer has been working on building a new automation for the SOC. What Scope should be selected in the SOAR Playbook Debugger during the playbook development to ensure consistency?

Options:

A.

New Events

B.

All Artifacts

C.

New Artifacts

D.

All Events

Questions # 12:

Which of the following identifies elements of the Detection Development Lifecycle (DDLC)?

Options:

A.

Research, Develop, Document, Test, Deploy

B.

Research, Design, Deploy, Validate

C.

Design, Develop, Deploy, Monitor, Maintain

D.

Design, Develop, Test, Deploy

Questions # 13:

MITRE D3FEND is designed to compliment MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?

Options:

A.

Harden, Detect, Exclude, Deceive, Eradicate

B.

Harden, Detect, Isolate, Disrupt, Evict

C.

Harden, Detect, Exclude, Define, Eradicate

D.

Harden, Detect, Isolate, Deceive, Evict

Questions # 14:

In order to perform a complete data assessment, an engineer ' s role within Splunk must have which of the following?

Options:

A.

The capability to edit macros.

B.

Access to applicable indexes.

C.

The capability to create Correlation Searches.

D.

Access to Knowledge Objects.

Questions # 15:

Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)

Options:

A.

Regular updates based on feedback

B.

Focusing solely on high-risk scenarios

C.

Collaborating with cross-functional teams

D.

Including detailed step-by-step instructions

E.

Excluding historical incident data

Questions # 16:

The following SPL is designed to report on a certain SOC metric. Which metric is the most likely topic for this report?

| tstats summariesonly=true earliest(_time) as _time

FROM datamodel=Incident_Management

BY " Notable_Events.Meta.rule_id "

| rename " Notable_Events.Meta.* " as " * "

| lookup update=true incident_updates_lookup rule_id OUTPUTNEW time

| search time=*

| stats earliest(_time) as create_time, min(time) as triage_time by rule_id

| eval diff=triage_time-create_time,

stat_type=if(

create_time < relative_time(now(), " -7d@d " ),

" past " ,

" current "

),

past=if(stat_type= " past " , 1, 0),

current=if(stat_type= " current " , 1, 0),

past_diff=if(stat_type= " past " , diff, 0),

current_diff=if(stat_type= " current " , diff, 0)

| stats sum(past) AS past,

sum(current) AS current,

sum(past_diff) AS past_diff,

sum(current_diff) AS current_diff

| eval past=round(past_diff/past/60),

current=round(current_diff/current/60)

| table past, current

| transpose

Options:

A.

Mean time to Triage

B.

Mean time to Respond

C.

Mean time to Resolve

D.

Dwell Time

Questions # 17:

An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?

Options:

A.

The endpoint that the asset is configured for does not exist.

B.

Either the asset username or password is incorrect.

C.

The asset endpoint requires a token rather than a username and password.

D.

Asset credentials do not have adequate permissions.

Questions # 18:

Which fields are used to determine asset priority, when priority is assigned through an asset and identity lookup?

Options:

A.

dest, src, or dvc

B.

dest, src, or tag

C.

user or src_user

D.

dest_user or src_user

Questions # 19:

What is Enterprise Security ' s default way of determining the urgency of a finding (notable event)?

Options:

A.

Multiply the risk score of a detection by how many times it has run.

B.

Leverage the scheduling priority of the detection to know what ' s most critical.

C.

Add risk scores for associated objects within a network.

D.

Take into account the priority assigned to the asset/identity as well as the severity value assigned to the finding.

Questions # 20:

Based on this example image, if it is detected that a member has been added to a security-enabled local group, how many risk events will be created?

Question # 20

Options:

A.

20

B.

1

C.

10

D.

2

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.