Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Splunk Certified Cybersecurity Defense Engineer

Last Update 23 hours ago Total Questions : 105

The Splunk Certified Cybersecurity Defense Engineer content is now fully updated, with all current exam questions added 23 hours ago. Deciding to include SPLK-5002 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SPLK-5002 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SPLK-5002 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Splunk Certified Cybersecurity Defense Engineer practice test comfortably within the allotted time.

Question # 21

An engineer creates a new event type. What defines the association of this event type to an applicable data model?

A.

The tag(s)

B.

The search string

C.

The field alias

D.

The saved search name

Question # 22

What is Enterprise Security ' s default way of determining the urgency of a finding (notable event)?

A.

Multiply the risk score of a detection by how many times it has run.

B.

Leverage the scheduling priority of the detection to know what ' s most critical.

C.

Add risk scores for associated objects within a network.

D.

Take into account the priority assigned to the asset/identity as well as the severity value assigned to the finding.

Question # 23

What external support consideration should an engineer account for if they plan to automate the disabling of a system or user?

A.

Communicate the actions to the IT Help Desk.

B.

Enable logging on the playbook.

C.

Validate that the system or user is not already disabled.

D.

Add the " support " tag to the playbook.

Question # 24

What provides consistency for data mapping applied to data model and saved search exports between Splunk Enterprise Security and Splunk SOAR?

A.

Field aliases

B.

Field labels

C.

Global field aliases

D.

Global field mappings

Question # 25

The SOC notices over the course of an investigation there are numerous logs similar to the following:

UDP: query: reallybad.c2.com IN A response: SERVFAIL

What detection should be created to alert on this behavior for the future?

A.

Excessive DNS Failures

B.

Excessive Authentication Failures

C.

Excessive Network Failures

D.

Excessive Endpoint Failures

Question # 26

When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?

A.

Input

B.

Automation

C.

Process

D.

Response

Question # 27

The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer ensure this activity automatically produces findings in the future?

A.

Create a SOAR playbook to identify events matching the activity and assign an urgency.

B.

Create a correlation search to produce notable events for the activity.

C.

Create a SOAR playbook to assign risk modifiers for events matching the activity.

D.

Create a risk modifier for events matching the activity.

Question # 28

When building detections using the Authentication Data Model, which values are recommended for use against the action field?

A.

allowed, blocked, processing, error

B.

success, failure, pending, error

C.

allowed, blocked, inactivity, error

D.

success, denied, pending, error

Question # 29

The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?

A.

Workbooks

B.

Events

C.

Cases

D.

Incidents

Question # 30

Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?

A.

Existing investigation actions

B.

MITRE ATT & CK® framework

C.

Existing Standard Operating Procedure

D.

CIS Framework

Go to page: