SPLK-5002 Exam Questions
117 real SPLK-5002 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Advanced Threat Hunting and Analytics
What is Enterprise Security's default way of determining the urgency of a finding (notable event)?
notable eventsurgency calculationasset priorityseverity - Question #52Security Automation and Orchestration
Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?
SOAR playbooksSOPplaybook designincident response - Question #53Threat Intelligence Integration
In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?
threat intelligencefile_intelES lookupsthreat lookup tables - Question #54Advanced Threat Hunting and Analytics
The SOC manager has a desire to measure mean time to acknowledge findings (notable events) in order to meet a desired service level objective. Which two fields can be used to measu...
MTTASLOnotable eventsSOC metrics - Question #55Advanced Security Data Onboarding
An engineer has discovered that an acquired company uses a duplicate IP address space. Which feature of the asset and identity framework could be turned on that would allow for the...
entity zonesasset identity frameworkIP overlapnetwork segmentation - Question #56Advanced Threat Hunting and Analytics
The following SPL is designed to report on a certain SOC metric. Which metric is the most likely topic for this report?
SPLMTTISOC metricsnotable triage - Question #57Custom Content Development
Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?
SPL macrosknowledge objectssearch reuseSPL optimization - Question #58Security Automation and Orchestration
An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?
EDR integrationSOAR asset actionsendpoint securityplaybook actions - Question #59Security Automation and Orchestration
Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?
automationtriageincident response lifecyclemanual-to-automation - Question #60Custom Content Development
What must be configured as a setting in a correlation search for a notable to be generated?
correlation searchnotable eventsadaptive response actionES configuration - Question #61Performance Optimization and Troubleshooting
An engineer is examining a correlation search as a part of a detection review, and sees that it is configured in the following fashion: Which of the following is true about this co...
correlation search schedulingtime range gapdetection coveragesearch frequency - Question #62Threat Intelligence Integration
Engineers are commonly asked to turn data sources like EDR alerts into risk events. Doing so requires a dynamic mapping of the signatures in the rule to MITRE ATT&CK®. Which of the...
MITRE ATT&CK mappingrisk eventsEDR annotationsannotations field - Question #63Security Automation and Orchestration
There are multiple methods for communicating data with a REST Endpoint. In the above screenshot what is the name of the key value pairs represented after the question mark in the U...
REST APIURL query parametersHTTP requestsAPI integration - Question #64Threat Intelligence Integration
A threat actor group has begun a campaign that is relevant to an organization. How can the organization's engineer raise the risk score for corresponding intelligence matches in th...
threat collection weightrisk scoringthreat intelligence tuningES threat framework - Question #65Advanced Threat Hunting and Analytics
The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?
MTTRSOC efficiencySOC metricsoperational KPIs - Question #66Advanced Threat Hunting and Analytics
Which of the following is a reason to utilize ES risk framework as a part of detection building?
risk frameworkdetection buildingrisk-based alertingbusiness impact prioritization - Question #67Security Automation and Orchestration
When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?
SOAR case managementrisk notablesevent correlationinvestigation workflow - Question #68Performance Optimization and Troubleshooting
Consider the following series of events: 4:00 GMT Detection runs for interval 3:30-4:00 4:30 GMT Detection runs for interval 4:00-4:30 4:35 GMT Event 1 occurs on an endpoint 4:45 G...
detection schedulinglog ingestion delaytime window sizingdata latency - Question #69Security Automation and Orchestration
An effective method for building automation workflows is to follow the OODA (Observe, Orient, Decide, Act) loop stages. When transitioning between the Decide and Act stages, what a...
OODA loopautomation workflow designexemption validationSOAR orchestration - Question #70Advanced Threat Hunting and Analytics
What is the best method to operationalize the results of a threat hunt for daily use by SOC analysts?
threat huntingdetection operationalizationSOC workflowhunt-to-detect - Question #71Custom Content Development
How can an engineer verify if results will return for a potential detection based on historical events within the organization?
detection validationhistorical dataproduction testingdetection development - Question #72Advanced Security Data Onboarding
Which of the following is not a type of metadata that can be returned by the metadata command?
metadata commandSplunk commandsdata explorationsourcetypes - Question #73Threat Intelligence Integration
MITRE D3FENDTM is designed to compliment MITRE's list of adversarial tactics, techniques, and common knowledge (ATT&CK®). Which tactics are associated with MITRE D3FENDTM in order...
MITRE D3FENDdefensive tacticsATT&CKthreat frameworks - Question #74Advanced Threat Hunting and Analytics
Below is an example of a sysmon process create log. Which EventCode would be associated to this log entry?
SysmonEventCodeprocess creationWindows logging - Question #75Advanced Threat Hunting and Analytics
Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which EventСode associated to PowerShel...
PowerShell Script Block LoggingEventCode 4104pass-the-hashEmpire - Question #76Performance Optimization and Troubleshooting
When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?
security metricsKPIKRIperimeter firewall - Question #77Custom Content Development
Which stash event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?
stash eventsadaptive responsecorrelation searchsearch_sid - Question #78Advanced Security Data Onboarding
An engineer needs to create a new report capturing the vendors and products that detect a particular CVE in their environment. How can they ensure that their search associated with...
tstats commanddata model accelerationVulnerabilities data modelCIM - Question #79Custom Content Development
Which of the following identifies elements of the Detection Development Lifecyle (DDLC)?
Detection Development LifecycleDDLCdetection engineeringworkflow - Question #80Custom Content Development
The SOC notices over the course of an investigation there are numerous logs like the following: 14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query: reallybad.c2.com IN...
DNS detectionSERVFAILC2 communicationdetection creation - Question #81Advanced Security Data Onboarding
When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform c...
CIM accelerationdata model accelerationsummary rangecolumn stores - Question #82Security Automation and Orchestration
When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?
SOAR playbookMission ControlEnterprise Securityresponse playbook - Question #83Advanced Threat Hunting and Analytics
What does the following search do?
process analysisparent-child processSPL searchprocess tree - Question #84Custom Content Development
An engineer has been asked to build a new dashboard after an increase in login failures across the organization's Microsoft Azure domain. They need to construct a search to only di...
Azure ADgeostatsdashboard creationfailed logins - Question #85Security Automation and Orchestration
A cyber defense engineer plays a role in maintaining a secure SOAR Cloud configuration. Which network security statement is correct about SOAR Cloud?
SOAR CloudAutomation BrokerSSL connectionsnetwork security - Question #86Advanced Security Data Onboarding
When building detections using the Authentication Data Model, which values are recommended for use against the actions field?
CIMAuthentication data modelaction field valuesdata normalization - Question #87Threat Intelligence Integration
Which Enterprise Security components provide enrichment to the Risk Framework?
Risk FrameworkAssets and IdentitiesRisk FactoringEnterprise Security - Question #88Advanced Security Data Onboarding
What is the primary purpose of data indexing in Splunk?
data indexingSplunk indexingsearch optimizationdata storage - Question #89Security Automation and Orchestration
Which features are crucial for validating integrations in Splunk SOAR? (Choose three)
SOAR integration validationAPI connectivityauthentication verificationautomated actions - Question #90Custom Content Development
How can you incorporate additional context into notable events generated by correlation searches?
notable eventsfield enrichmentcorrelation searchesEnterprise Security - Question #91Advanced Threat Hunting and Analytics
What is the primary purpose of correlation searches in Splunk?
correlation searchespattern identificationmultiple data sourcesSIEM - Question #92Security Automation and Orchestration
Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)
SOPsincident responsedocumentationcross-functional collaboration - Question #93Security Automation and Orchestration
A new playbook needs to be developed for automated phishing analysis and response. Configured in SOAR are integrations with Splunk Enterprise Security and actions from assets that...
SOAR playbookphishing analysisautomated responseworkflow design - Question #94Custom Content Development
Which of the following macro values will exclude all of the company networks if it is called from the following search? index=firewall sourcetype=pan:traffic NOT "company_networks"
SPL macrosnetwork filteringNOT operatorsearch syntax - Question #95Advanced Threat Hunting and Analytics
Risk scores are associated with how many levels of risk in Enterprise Security by default?
risk scoresEnterprise Securityrisk levelsseverity - Question #96Security Automation and Orchestration
While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation th...
adaptive response actionsinput playbooksURL filteringSOAR - Question #97Custom Content Development
What is one method used in ESCU content to calculate a risk score when creating a detection that uses the Risk Analysis adaptive response action?
risk scoringESCURisk Analysis adaptive responseimpact confidence - Question #98Advanced Security Data Onboarding
Lookups append fields from an external source to events based on the values of fields that are already present in those events. What are the four supported lookup types?
lookupsCSV lookupKV StoreGeospatial lookup - Question #99Custom Content Development
When creating a detection, how might an engineer ensure that all possible contextual fields about a given asset and identity are added to a risk event?
CIM fieldsasset identityrisk eventsdetection engineering - Question #100Custom Content Development
Which of the following is a reason to utilize an index-based search (index=...) over a data model search (| tstats...) in a detection?
index-based searchtstatsdata modelraw data fields