Splunk Certified Cybersecurity Defense Engineer - SPLK-5002 Exam Practice Test

In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Consider the following series of events:
4:00 GMT Detection runs for interval 3:30-4:00
4:30 GMT Detection runs for interval 4:00-4:30
4:35 GMT Event 1 occurs on an endpoint
4:45 GMT Event 1 is indexed
5:00 GMT Detection runs for interval 4:30-5:00
5:05 GMT Event 1 finding is added to ES with timestamp 4:35
5:24 GMT Event 2 occurs on an endpoint
5:30 GMT Detection runs for interval 5:00-5:30
5:35 GMT Event 2 is indexed
6:00 GMT Detection runs for interval 5:30-6:00
What is the problem with the detection schedule chosen and how can it be solved?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An engineer wants to track and report on all authentication to corporate assets and wants to prioritize critical assets without significantly increasing the number of findings created. What process could be used to accomplish this goal?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP
403 response code. Which of the following is a possible cause of the error code?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
MITRE D3FEND is designed to compliment MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
What does the following search do?
source=WinEventLog:security* sourcetype= " WinEventLog* " EventCode=4688
| stats count, values(process) as process by parent_process_name
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
When building detections using the Authentication Data Model, which values are recommended for use against the action field?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An engineer is writing a correlation search and needs to use T1059 from MITRE ATT & CK as a field in Incident Review. Assuming they are writing a correlation search that does not use the Risk data model, which example statement should be appended to the correlation search?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
What is the best method to operationalize the results of a threat hunt for daily use by SOC analysts?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0