SPLK-5002 Exam Questions
117 real SPLK-5002 exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #101Advanced Threat Hunting and Analytics
Which field in the risk index is used to describe the activity within a finding?
risk indexrisk_reasonrisk fieldsrisk framework - Question #102Performance Optimization and Troubleshooting
Which REST call will show a list of alerts with their specific commands, app, and title?
REST APIalert actionsSPL RESTSplunk admin - Question #103Security Automation and Orchestration
A Splunk administrator needs to integrate a third-party vulnerability management tool to automate remediation workflows. What is the most efficient first step?
REST APISOAR integrationvulnerability managementremediation workflows - Question #104Advanced Security Data Onboarding
Which sourcetype configurations affect data ingestion? (Choose three)
sourcetype configurationevent breakingtimestamp extractionline merging - Question #105Advanced Threat Hunting and Analytics
What is a key feature of effective security reports for stakeholders?
security reportingstakeholder communicationexecutive summariesactionable insights - Question #106Security Automation and Orchestration
Which Splunk feature enables integration with third-party tools for automated response actions?
workflow actionsthird-party integrationautomated responseEnterprise Security - Question #107Custom Content Development
Which action improves the effectiveness of notable events in Enterprise Security?
notable eventssuppression rulesfalse positivesEnterprise Security - Question #108Advanced Security Data Onboarding
What field is used by default to direct data into CIM data model datasets?
CIMdata modeltag fielddata normalization - Question #109Performance Optimization and Troubleshooting
An engineer receives a report that the "Traffic over time by action" dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they...
data model accelerationNetwork Trafficdashboard troubleshootingCIM compliance - Question #110Security Automation and Orchestration
What should a security engineer prioritize when building a new security process?
security process designcompliance alignmentsecurity frameworkpolicy - Question #111Custom Content Development
Which features of Splunk are crucial for tuning correlation searches? (Choose three)
correlation search tuningthresholdsnotable eventssearch optimization - Question #112Security Automation and Orchestration
A security analyst wants to validate whether a newly deployed SOAR playbook is performing as expected. What steps should they take?
SOAR playbookplaybook validationincident responsesimulation testing - Question #113Advanced Threat Hunting and Analytics
What are the benefits of incorporating asset and identity information into correlation searches? (Choose two)
asset contextidentity enrichmentcorrelation searchrisk prioritization - Question #114Advanced Threat Hunting and Analytics
A company wants to implement risk-based detection for privileged account activities. What should they configure first?
risk-based detectionprivileged accountsasset identitythreat detection - Question #115Threat Intelligence Integration
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?
threat intelligenceKV storeFQDNhttp_intel - Question #116Performance Optimization and Troubleshooting
When building a metrics dashboard for the SOC manager, which metric would represent how long it takes to fully complete an investigation?
SOC metricsMTTRincident resolutionKPIs - Question #117Advanced Threat Hunting and Analytics
During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is...
Analytic Storiesransomware detectiondetection groupingthreat correlation