Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Splunk Cybersecurity Defense Analyst SPLK-5002 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SPLK-5002 Premium Access

View all detail and faqs for the SPLK-5002 exam


762 Students Passed

84% Average Score

94% Same Questions
Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?

Options:

A.

orig_sid

B.

risk_sid

C.

search_sid

D.

result_sid

Questions # 32:

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

Options:

A.

A raw-event search followed by aggregation.

B.

A non-index-grouped metadata search.

C.

An index=* event search followed by stats.

D.

A tstats search returning sourcetypes and grouping them by index.

Questions # 33:

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:

A.

Perimeter firewalls should be measured on both the number of connections they permit and the number they block.

B.

Perimeter firewalls are exposed to the Internet and therefore subject to automated scanners and attack tools.

C.

The metric is too high level and should instead be broken down by the type of block.

D.

This is a Key Result Indicator, not a KPI; it measures the results of the perimeter firewall ' s actions rather than the performance of the firewall.

Questions # 34:

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?

Options:

A.

Supporting add-on for MITRE ATT & CK

B.

Splunk Security Essentials App

C.

Enterprise Security

D.

Enterprise Security Content Update App

Questions # 35:

A SOC ' s Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to gain efficiency through automation?

Options:

A.

Automatically assign phishing-tagged findings to analysts to begin manual collection.

B.

Automatically send an email notification for all findings containing the phishing tag.

C.

Use a SOAR playbook to handle the Splunk Attack Analyzer submission and data-collection steps and make the information available to an assigned analyst.

D.

Use a SOAR playbook to submit the email to PhishTank and have it perform the Splunk Attack Analyzer submission.

Questions # 36:

When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?

Options:

A.

Input

B.

Automation

C.

Process

D.

Response

Questions # 37:

When creating detections, which of the following sequences would result in the most performant SPL query?

Options:

A.

Define base query, combine/summarize data, minimize data, execute calculations, format the data

B.

Define base query, minimize data, combine/summarize data, execute calculations, format the data

C.

Define base query, minimize data, combine/summarize data, format the data, execute calculations

D.

Define base query, minimize data, format the data, combine/summarize data, execute calculations

Questions # 38:

Which of the following can process data from configured containers using an automated sequence of actions?

Options:

A.

Cases

B.

Workbooks

C.

Containers

D.

Playbooks

Questions # 39:

How does Mission Control decipher which response template to assign to findings?

Options:

A.

This is determined when creating a detection in ES, which gets carried over to Mission Control.

B.

Mission Control uses AI to decipher which response templates are assigned.

C.

Response templates are assigned to specific incident types.

D.

The only way to configure this is with SOAR.

Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.