Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Splunk Cybersecurity Defense Analyst SPLK-5002 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which features are crucial for validating integrations in Splunk SOAR? (Choose three)

Options:

A.

Testing API connectivity


B.

Monitoring data ingestion rates


C.

Verifying authentication methods


D.

Evaluating automated action performance


E.

Increasing indexer capacity


Expert Solution
Questions # 22:

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

Options:

A.

Status, Owner


B.

Urgency, Status


C.

Severity, Owner


D.

User, Status


Expert Solution
Questions # 23:

An effective method for building automation workflows is to follow the OODA (Observe, Orient, Decide, Act) loop stages. When transitioning between the Decide and Act stages, what additional step should be included before automating the Act stage?

Options:

A.

Validate response data paths from the Decide stage.


B.

Validate if the asset, identity, or service has an exemption.


C.

Create a new automation playbook.


D.

Create a new response template.


Expert Solution
Questions # 24:

Which tool can help identify known tactics, techniques, and procedures that a threat group is most likely to use when targeting a financial organization?

Options:

A.

The MITRE ATT & CK® Posture panel within Mission Control ' s Incident Review page


B.

The MITRE ATT & CK® matrix ' s industry heatmap in Splunk Security Essentials


C.

The Lockheed Martin Cyber Kill Chain® Posture panel within Enterprise Security ' s Incident Review page


D.

Splunk Threat Intelligence Management


Expert Solution
Questions # 25:

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

Options:

A.

A hierarchical organization chart


B.

Infrastructure architecture diagrams


C.

Application architecture diagrams


D.

Business Continuity or Disaster Recovery plan


Expert Solution
Questions # 26:

Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which EventCode associated to PowerShell Script Block Logging would be used to detect this activity?

Options:

A.

EventCode=4126


B.

EventCode=4168


C.

EventCode=4624


D.

EventCode=4104


Expert Solution
Questions # 27:

A SOC ' s Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to gain efficiency through automation?

Options:

A.

Automatically assign phishing-tagged findings to analysts to begin manual collection.


B.

Automatically send an email notification for all findings containing the phishing tag.


C.

Use a SOAR playbook to handle the Splunk Attack Analyzer submission and data-collection steps and make the information available to an assigned analyst.


D.

Use a SOAR playbook to submit the email to PhishTank and have it perform the Splunk Attack Analyzer submission.


Expert Solution
Questions # 28:

An engineer creates a new event type. What defines the association of this event type to an applicable data model?

Options:

A.

The tag(s)


B.

The search string


C.

The field alias


D.

The saved search name


Expert Solution
Questions # 29:

An engineer receives a report that the “Traffic over time by action” dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they are CIM compliant. What other configuration may be missing?

Options:

A.

The Network Sessions data model should be accelerated.


B.

The Performance data model is missing the network dataset.


C.

The Network Traffic data model should be accelerated.


D.

The Network Sessions data model has been deleted.


Expert Solution
Questions # 30:

What must be configured as a setting in a correlation search for a notable to be generated?

Options:

A.

A SOAR playbook must execute against the notable.


B.

Nothing; the correlation search will generate a notable automatically as an outcome.


C.

An Adaptive Response Action must be configured to enable the notable generation.


D.

The search must end with a | notable SPL command.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions