Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Splunk SPLK-5002 Practice Exam with Questions & Answers

Questions 1

Which of the following actions will allow access to a list of alert actions via the API?

Options:
A.

| rest /services/alerts/adaptive_response_action

B.

| rest /services/alerts/correlationsearches

C.

| rest /services/alerts/alert actions/_acl

D.

| rest /services/alerts/alert_actions

Splunk SPLK-5002 Premium Access
Questions 2

Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?

Options:
A.

Focus efforts on the least impactful threat vectors.

B.

Use the MITRE ATT & CK Framework to evaluate the organization ' s risk appetite.

C.

Evaluate the threat process lifecycle solely from predefined technical profiles.

D.

Evaluate the threat process lifecycle based on contextual business and industry knowledge.

Questions 3

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

Options:
A.

A hierarchical organization chart

B.

Infrastructure architecture diagrams

C.

Application architecture diagrams

D.

Business Continuity or Disaster Recovery plan

Questions 4

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

Options:
A.

service_intel

B.

http_intel

C.

certificate_intel

D.

ip_intel

Questions 5

The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer ensure this activity automatically produces findings in the future?

Options:
A.

Create a SOAR playbook to identify events matching the activity and assign an urgency.

B.

Create a correlation search to produce notable events for the activity.

C.

Create a SOAR playbook to assign risk modifiers for events matching the activity.

D.

Create a risk modifier for events matching the activity.

Questions 6

An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?

Options:
A.

Block device, remove email, detonate URL, get indicator

B.

Block hash, block process, quarantine device, get indicator

C.

Block URL, block subdomain, quarantine device, get indicator, detonate URL

D.

Block hash, reset user password, quarantine device, get indicator

Questions 7

Which syntax is correct to create two new rows on an existing threat intelligence collection?

Options:
A.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] ' -G -X

B.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] '

C.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= " [{ " src_user " : " user_new " , " subject " : " click this " },{ " src_user " : " user2_new " , " subject " : " click this " }] "

D.

curl -k -u admin\:pass https://localhost:8089/services/data/threat_intel/item/email_intel -d item= ' [{ " src_user " : " user_new " , " subject " : " click this " }] ' -G -X

Questions 8

An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?

Options:
A.

The endpoint that the asset is configured for does not exist.

B.

Either the asset username or password is incorrect.

C.

The asset endpoint requires a token rather than a username and password.

D.

Asset credentials do not have adequate permissions.

Questions 9

Which of the following is a methodology to help prevent malicious lateral movement?

Options:
A.

Breakglass

B.

Lockheed Martin Cyber Kill Chain®

C.

MITRE ATT & CK®

D.

Zero Trust

Questions 10

An effective method for building automation workflows is to follow the OODA (Observe, Orient, Decide, Act) loop stages. When transitioning between the Decide and Act stages, what additional step should be included before automating the Act stage?

Options:
A.

Validate response data paths from the Decide stage.

B.

Validate if the asset, identity, or service has an exemption.

C.

Create a new automation playbook.

D.

Create a new response template.