Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Cybersecurity Defense Analyst SPLK-5002 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?

Options:

A.

Focus efforts on the least impactful threat vectors.


B.

Use the MITRE ATT & CK Framework to evaluate the organization ' s risk appetite.


C.

Evaluate the threat process lifecycle solely from predefined technical profiles.


D.

Evaluate the threat process lifecycle based on contextual business and industry knowledge.


Expert Solution
Questions # 2:

A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user-reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?

Options:

A.

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block any malicious URLs and processes with the proxy and EDR solutions


B.

Submit the user reported email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions


C.

Submit the email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions


D.

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block all URLs and processes with the proxy and EDR solutions


Expert Solution
Questions # 3:

A Detection Engineer works closely with SOC leads to define expected analyst workflow, often documented as a Standard Operating Procedure (SOP). Which capability can be used to document expected analyst actions in an investigation?

Options:

A.

Response templates


B.

Correlation Search Editor


C.

Adaptive response actions


D.

Investigation notes


Expert Solution
Questions # 4:

Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?

Options:

A.

Rendering a verdict


B.

Triage


C.

Containment


D.

Remediation


Expert Solution
Questions # 5:

An engineer has been working on building a new automation for the SOC. What Scope should be selected in the SOAR Playbook Debugger during the playbook development to ensure consistency?

Options:

A.

New Events


B.

All Artifacts


C.

New Artifacts


D.

All Events


Expert Solution
Questions # 6:

Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?

Options:

A.

Knowledge objects


B.

Commands


C.

Lookups


D.

Macros


Expert Solution
Questions # 7:

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

Options:

A.

user_id


B.

user


C.

action


D.

identity


Expert Solution
Questions # 8:

What is one method used in ESCU content to calculate a risk score when creating a detection that uses the Risk Analysis adaptive response action?

Options:

A.

Risk Score = (Impact × Confidence / 100)


B.

Risk Score = (Risk Object Severity × Confidence / 100)


C.

Risk Score = (Risk Object Priority × Confidence / 100)


D.

Risk Score = (Impact × Priority / 100)


Expert Solution
Questions # 9:

A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?

Options:

A.

Enterprise Security Content Update App


B.

Splunk Security Essentials App


C.

Enterprise Security


D.

Supporting add-on for MITRE ATT & CK


Expert Solution
Questions # 10:

What framework in Enterprise Security allows engineers to build detections using known malicious IOCs, comparing them to event logs to find suspicious behavior?

Options:

A.

Asset & Intelligence Framework


B.

Incident Management Framework


C.

Threat Intelligence Framework


D.

OSINT Framework


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions