Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free Splunk Certified Cybersecurity Defense Engineer Practice Questions

Exams4sure Dumps

Exam style questions across every SPLK-5002 domain

Last Update 1 day ago
Total Questions : 105

Start with our free SPLK-5002 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Cybersecurity Defense Analyst exam. Each SPLK-5002 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Splunk weak domains, see where you're losing marks, and build a focused study plan in minutes.

SPLK-5002 PDF

SPLK-5002 PDF (Printable)
$54.25
$154.99

SPLK-5002 Testing Engine

SPLK-5002 PDF (Printable)
$59.5
$169.99

SPLK-5002 PDF + Testing Engine

SPLK-5002 PDF (Printable)
$74.55
$212.99
Question # 1

A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that pull in user-reported emails, perform automated threat analysis, add blocks on the proxy, and an EDR vendor to take various actions. Which would be the best workflow for the new playbook?

Options:

A.  

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block any malicious URLs and processes with the proxy and EDR solutions

B.  

Submit the user reported email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions

C.  

Submit the email from Splunk Enterprise Security

Search the mail system for all users that received the email

Review results from the automated threat analysis

Block any malicious URLs and processes with the proxy and EDR solutions

D.  

Ingest the email from the mail vendor

Detonate email in the automated threat analysis system and collect verdict, looking for malicious indicators

Search the mail system for all users that received the email

Block all URLs and processes with the proxy and EDR solutions

Discussion 0
Question # 2

Which of the following actions will allow access to a list of alert actions via the API?

Options:

A.  

| rest /services/alerts/adaptive_response_action

B.  

| rest /services/alerts/correlationsearches

C.  

| rest /services/alerts/alert actions/_acl

D.  

| rest /services/alerts/alert_actions

Discussion 0
Question # 3

Which syntax is correct to create two new rows on an existing threat intelligence collection?

Options:

A.  

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] ' -G -X

B.  

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] '

C.  

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= " [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] "

D.  

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] ' -G -X

Discussion 0
Question # 4

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

Options:

A.  

Parameters

B.  

Payload

C.  

Headers

D.  

KV Elements

Discussion 0
Question # 5

When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?

Options:

A.  

Include the standard CIM fields for assets and identities in the detection output.

B.  

Use an identity lookup to return all available identity information in the detection output.

C.  

Use an asset lookup to return all available asset information in the detection output.

D.  

Call an Active Directory adaptive response action to perform a real-time update.

Discussion 0
Question # 6

Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?

Options:

A.  

Rendering a verdict

B.  

Triage

C.  

Containment

D.  

Remediation

Discussion 0
Question # 7

The SOC notices over the course of an investigation there are numerous logs similar to the following:

UDP: query: reallybad.c2.com IN A response: SERVFAIL

What detection should be created to alert on this behavior for the future?

Options:

A.  

Excessive DNS Failures

B.  

Excessive Authentication Failures

C.  

Excessive Network Failures

D.  

Excessive Endpoint Failures

Discussion 0
Question # 8

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

Options:

A.  

A raw-event search followed by aggregation.

B.  

A non-index-grouped metadata search.

C.  

An index=* event search followed by stats.

D.  

A tstats search returning sourcetypes and grouping them by index.

Discussion 0
Question # 9

Which of the following identifies elements of the Detection Development Lifecycle (DDLC)?

Options:

A.  

Research, Develop, Document, Test, Deploy

B.  

Research, Design, Deploy, Validate

C.  

Design, Develop, Deploy, Monitor, Maintain

D.  

Design, Develop, Test, Deploy

Discussion 0
Question # 10

When should a detection be reviewed or retuned after deployment?

Options:

A.  

Every 30 days.

B.  

Only if it has generated a large amount of false positives.

C.  

As defined by the established detection lifecycle.

D.  

Only if it hasn ' t generated a finding after several weeks.

Discussion 0

Free Exams Sample Questions