75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Splunk Cybersecurity Defense Analyst SPLK-5002 Questions and answers with Dumpstech

Exam SPLK-5002 Premium Access

View all detail and faqs for the SPLK-5002 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which action improves the effectiveness of notable events in Enterprise Security?

Options:

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Questions # 22:

What field is used by default to direct data into CIM data model datasets?

Options:

A.

tag

B.

sourcetype

C.

source

D.

dataset

Questions # 23:

How does Mission Control decipher which response template to assign to findings?

Options:

A.

This is determined when creating a detection in ES, which gets carried over to Mission Control.

B.

Mission Control uses AI to decipher which response templates are assigned.

C.

Response templates are assigned to specific incident types.

D.

The only way to configure this is with SOAR.

Questions # 24:

Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they ' ve been utilizing for testing a detection named TestSearchDevelopment?

Options:

A.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/ -X DELETE

B.

Splunk endpoints cannot be disabled.

C.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X POST

D.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X PUT

Questions # 25:

Which field in the risk index is used to describe the activity within a finding?

Options:

A.

risk_message

B.

risk_description

C.

risk_object

D.

risk_reason

Questions # 26:

When building detections using the Authentication Data Model, which values are recommended for use against the action field?

Options:

A.

allowed, blocked, processing, error

B.

success, failure, pending, error

C.

allowed, blocked, inactivity, error

D.

success, denied, pending, error

Questions # 27:

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

Options:

A.

Status, Owner

B.

Urgency, Status

C.

Severity, Owner

D.

User, Status

Questions # 28:

Which of the following is a reason to utilize ES risk framework as a part of detection building?

Options:

A.

Help accelerate the run time of detections, allowing a faster mean time to detection.

B.

Create a feedback loop into threat intelligence to identify potential insider threats.

C.

Help prioritize security findings based on their potential business impact.

D.

Simplify SOAR automation and remediation, lowering the mean time to recover.

Questions # 29:

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

Options:

A.

Parameters

B.

Payload

C.

Headers

D.

KV Elements

Questions # 30:

A Detection Engineer works closely with SOC leads to define expected analyst workflow, often documented as a Standard Operating Procedure (SOP). Which capability can be used to document expected analyst actions in an investigation?

Options:

A.

Response templates

B.

Correlation Search Editor

C.

Adaptive response actions

D.

Investigation notes

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions