SPLK-5002 Exam Questions
117 real SPLK-5002 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Splunk Basics
Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?
Enterprise SecurityThreat Intelligenceadd-onSA-ThreatIntelligence - Question #2Splunk Basics
In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?
Risk-Based Alertingrisk factorEnterprise Securityrisk multiplier - Question #3Splunk Basics
In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the...
SOARplaybookHTTP POST methodsandbox analysis - Question #4Splunk Basics
What provides consistency for data mapping applied to data model and saved search exports between Splunk Enterprise Security and Splunk SOAR?
global field mappingsEnterprise SecuritySOAR integrationdata consistency - Question #5Splunk Basics
Which tool can help provide a baseline of the data sources in a given Splunk environment?
Security Essentialsdata inventorydata sourcesbaseline - Question #6Splunk Basics
An engineer is writing a correlation search and wants to use T1027 from MITRE ATT&CK® as a field in Incident Review. Assuming they are writing a correlation search that does not us...
correlation searchMITRE ATT&CKeval commandannotations - Question #7Splunk Basics
An automation engineer for the Wonderland SOC, has configured a new asset and is getting an HTTP 403 response code. Which of the following is the possible cause of this error code?
HTTP 403asset configurationpermissionsSOAR - Question #8Splunk Basics
Which of the following is a methodology to help prevent malicious lateral movement?
Zero Trustlateral movementsecurity methodologynetwork security - Question #9Splunk Basics
How does Mission Control decipher which response template to assign to findings?
Mission Controlresponse templatesincident typesES workflow - Question #10Advanced Security Data Onboarding
For detections that leverage a CIM data model, which aspect of the configuration is responsible for determining which indexes are being searched?
CIM data modelconstraint macroindex filteringdata model configuration - Question #11Custom Content Development
The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer...
correlation searchnotable eventsdetection engineeringthreat hunting - Question #12Threat Intelligence Integration
A detection engineer is using a threat defense informed strategy to define use cases. Which Splunk app would best facilitate their use case development process by cross referencing...
MITRE ATT&CKSplunk Security Essentialsuse case developmentthreat defense strategy - Question #13Custom Content Development
What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?
dashboard tokensdrilldowndashboard developmentcontextual values - Question #14Custom Content Development
A corporate laptop was disconnected from the internet Friday at 5PM local time. While offline, the user unknowingly opened a malicious file. The laptop came back online the followi...
event time configurationdetection tuninglookback periodoffline events - Question #15Custom Content Development
Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
Windows Event Code 4740account lockoutsdetection identificationWindows security - Question #16Security Automation and Orchestration
A SOC's Incident Response Standard Operating Procedure (SOP) calls for any phishing emails containing files to be detonated in Splunk Attack Analyzer for evaluation. Which of the f...
SOAR playbookphishing automationSplunk Attack Analyzerincident response SOP - Question #17Advanced Security Data Onboarding
Which fields are used to determine asset priority, when priority is assigned through an asset and identity lookup?
asset priorityasset identity lookupdest src dvc fieldsasset framework - Question #18Threat Intelligence Integration
What framework in Enterprise Security allows engineers to build detections using known malicious IOCs comparing them to event logs to find suspicious behavior?
Threat Intelligence FrameworkIOC matchingEnterprise Securitydetection framework - Question #19Security Automation and Orchestration
Which of the following can process data from configured containers using an automated sequence of actions?
SOAR playbookscontainersautomated actionsSOAR architecture - Question #20Security Automation and Orchestration
A Detection Engineer works closely with SOC leads to define expected analyst workflows, often documented as a Standard Operating Procedure (SOP). Which capability can be used to do...
response templatesanalyst workflowSOP documentationinvestigation management - Question #21Advanced Threat Hunting and Analytics
What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?
risk prioritizationbusiness continuitydisaster recoveryentity risk context - Question #22Performance Optimization and Troubleshooting
Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they've been utilizing for testing a detection named TestSearchDevelopment...
REST APIcURLdetection managementAPI endpoint disable - Question #23Custom Content Development
An engineer wants to track and report on all authentication to corporate assets, and wants to prioritize critical assets without significantly increasing the number of findings (no...
risk indexasset criticalityrisk-based alertingnotable event reduction - Question #24Advanced Security Data Onboarding
In the context of Splunk's Common Information Model (CIM), which constraint ensures that events from different data sources appear in the applicable data model?
CIM tagsdata model constraintevent normalizationdata source mapping - Question #25Threat Intelligence Integration
Which tool can help identify known tactics, techniques, and procedures that a threat group is most likely to use when targeting a financial organization?
MITRE ATT&CK heatmapindustry targetingSplunk Security Essentialsthreat group TTPs - Question #26Advanced Threat Hunting and Analytics
Based on the provided screenshot, it's discovered that different machines or accounts have been associated with the shown threat objects. Enterprise Security has identified that th...
Risk frameworkAssets and Identities frameworkentity resolutionthreat object correlation - Question #27Custom Content Development
An engineer notices that a detection is creating multiple findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findi...
correlation search throttlingduplicate findingsdetection tuningnotable event management - Question #28Advanced Threat Hunting and Analytics
Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
threat detection lifecycleTDIRbusiness contextrisk evaluation - Question #29Performance Optimization and Troubleshooting
Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?
tstats commandindex discoverysourcetype enumerationsearch efficiency - Question #30Advanced Security Data Onboarding
When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?
CIM field normalizationuser fielddata aggregationdetection engineering - Question #31Security Automation and Orchestration
The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of...
SOAR workbooksSOP standardizationanalyst workflowincident response - Question #32Advanced Threat Hunting and Analytics
Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?
Risk Incident Rulerisk indexrisk notablescorrelation search - Question #33Custom Content Development
One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide conte...
drill-down searchtriage contextnotable eventdetection engineering - Question #34Advanced Threat Hunting and Analytics
Which of the following traces specific stages of an attack lifecycle?
Cyber Kill Chainattack lifecyclethreat frameworkadversary tactics - Question #35Performance Optimization and Troubleshooting
An engineer adds a custom event status of 'Testing' and accidentally makes it the new default status. Their SOC calculates some metrics based on Notable status change sequences, st...
notable statusmean time to triagedwell timeSOC metrics - Question #36Security Automation and Orchestration
While working in Mission Control, an analyst is looking to add enrichment and contextualize the finding that is being worked. If they were to click the execute icon next to the "Mi...
SOAR playbook executionMission Controlenrichmentplaybook trigger - Question #37Security Automation and Orchestration
An engineer has been working on building a new automation for the SOC. What Scope should be selected in the SOAR Playbook Debugger during the playbook development to ensure consist...
SOAR playbook debuggerscope configurationplaybook developmentartifacts - Question #38Threat Intelligence Integration
Which syntax is correct to create two new rows on an existing threat intelligence collection?
threat intel REST APIcurl syntaxemail intel collectionthreat intel ingestion - Question #39Advanced Security Data Onboarding
An engineer creates a new event type. What defines the association of this event type to an applicable data model?
event typedata model associationtagsCIM mapping - Question #40Advanced Security Data Onboarding
In order to perform a complete data assessment, an engineer's role within Splunk must have which of the following?
data assessmentindex accessdata onboardingrole permissions - Question #41Advanced Threat Hunting and Analytics
The below search is used to tabulate the Risk Score by Entity. What is incorrect about this search?
risk-based alertingrisk_object fieldSPL syntaxsearch debugging - Question #42Advanced Threat Hunting and Analytics
Based on this example image, if it is detected that a member has been added to a security- enabled local group, how many risk events will be created?
risk event generationsecurity group detectionrisk scoringcorrelation search behavior - Question #43Security Automation and Orchestration
Which of the following actions will allow access to a list of alert actions via the API?
REST APIalert actionsadaptive responseSplunk management API - Question #44Custom Content Development
Utilizing a Standard Operating Procedure (SOP) is an effective way to ensure that analysts are responding to generated findings in a consistent and analytical manner. Where is the...
notable adaptive responseuseful linksSOP integrationanalyst guidance - Question #45Security Automation and Orchestration
What external support consideration should an engineer account for if they plan to automate the disabling of a system or user?
automation governanceIT coordinationdisable user playbookresponse orchestration - Question #46Performance Optimization and Troubleshooting
When creating detections, which of the following sequences would result in the most performant SPL query?
SPL query optimizationsearch performancedata minimizationdetection SPL - Question #47Custom Content Development
When should a detection be reviewed or retuned after deployment?
detection lifecycledetection tuningfalse positive managementdetection review cadence - Question #48Performance Optimization and Troubleshooting
If a correlation search cannot be run at the configured time, which scheduling option should an engineer use to ensure there are no backfill gaps in data?
continuous schedulingcorrelation search backfilldata gap preventionsearch scheduling - Question #49Advanced Security Data Onboarding
Which search command was used to generate the result in the image below?
datamodel commandSPL search commandsdata model queryingCIM data exploration - Question #50Performance Optimization and Troubleshooting
What cardinality of data should be used in an indexed field to optimize and speed up searches?
indexed fieldscardinalitysearch optimizationdata indexing