SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Questions and Answers
Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
Which REST call will show a list of alerts with their specific commands, app, and title?
An engineer needs to create a new report capturing the vendors and products that detect a particular CVE in their environment. How can they ensure that the search associated with the report only includes accelerated data?
If a correlation search cannot be run at the configured time, which scheduling option should an engineer use to ensure there are no backfill gaps in data?
An engineer adds a custom event status of ' Testing ' and accidentally makes it the new default status. Their SOC calculates some metrics based on Notable status change sequences, starting from the old default status of ' New ' . Which metrics can be affected by this mistake?
An engineer has been working on building a new automation for the SOC. What Scope should be selected in the SOAR Playbook Debugger during the playbook development to ensure consistency?
Which of the following is not a type of metadata that can be returned by the metadata command?
When creating detections, which of the following sequences would result in the most performant SPL query?
The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?
In the context of Splunk ' s Common Information Model (CIM), which construct ensures that events from different data sources appear in the applicable data model?
A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing detections with the MITRE ATT & CK Framework?
The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?
Which of the following macro values will exclude all of the company networks if it is called from the following search?
index=firewall sourcetype=pan\:traffic NOT " company_networks "
When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform creates its column stores?
Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which EventCode associated to PowerShell Script Block Logging would be used to detect this activity?
A Detection Engineer works closely with SOC leads to define expected analyst workflow, often documented as a Standard Operating Procedure (SOP). Which capability can be used to document expected analyst actions in an investigation?
A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user-reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?
What does the following search do?
source=WinEventLog:security* sourcetype= " WinEventLog* " EventCode=4688
| stats count, values(process) as process by parent_process_name
What external support consideration should an engineer account for if they plan to automate the disabling of a system or user?
What must be configured as a setting in a correlation search for a notable to be generated?
Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?
In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?
Which fields are used to determine asset priority, when priority is assigned through an asset and identity lookup?
A SOC ' s Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to gain efficiency through automation?
Below is an example of a Sysmon process create log. Which EventCode would be associated with this log entry?
