Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Splunk SPLK-5002 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they ' ve been utilizing for testing a detection named TestSearchDevelopment?

Options:
A.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/ -X DELETE

B.

Splunk endpoints cannot be disabled.

C.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X POST

D.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X PUT

Splunk SPLK-5002 Premium Access
Questions 12

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

Options:
A.

Status, Owner

B.

Urgency, Status

C.

Severity, Owner

D.

User, Status

Questions 13

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:
A.

Perimeter firewalls should be measured on both the number of connections they permit and the number they block.

B.

Perimeter firewalls are exposed to the Internet and therefore subject to automated scanners and attack tools.

C.

The metric is too high level and should instead be broken down by the type of block.

D.

This is a Key Result Indicator, not a KPI; it measures the results of the perimeter firewall ' s actions rather than the performance of the firewall.

Questions 14

An engineer has been working on building a new automation for the SOC. What Scope should be selected in the SOAR Playbook Debugger during the playbook development to ensure consistency?

Options:
A.

New Events

B.

All Artifacts

C.

New Artifacts

D.

All Events

Questions 15

What is the best method to operationalize the results of a threat hunt for daily use by SOC analysts?

Options:
A.

Create monthly reports based on the documented findings.

B.

Communicate findings based on the hunt.

C.

Communicate gaps to the architecture teams.

D.

Create detections based on the documented findings.

Questions 16

An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?

Options:
A.

Correlation search throttling

B.

Correlation search priority

C.

Adaptive risk modifier

D.

Adaptive response actions

Questions 17

Based on the provided screenshot, it ' s discovered that different machines or accounts have been associated with the shown threat objects.

SPLK-5002 Question 17

Enterprise Security has identified that these machines and accounts all point back to one owner - Fyodor. Which two frameworks in ES are responsible for programmatically associating this information together?

Options:
A.

Threat Intelligence, Assets & Identities

B.

Risk, Incident Review

C.

Risk, Assets & Identities

D.

Threat Intelligence, Risk

Questions 18

Which action improves the effectiveness of notable events in Enterprise Security?

Options:
A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Questions 19

How does Mission Control decipher which response template to assign to findings?

Options:
A.

This is determined when creating a detection in ES, which gets carried over to Mission Control.

B.

Mission Control uses AI to decipher which response templates are assigned.

C.

Response templates are assigned to specific incident types.

D.

The only way to configure this is with SOAR.

Questions 20

Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?

Options:
A.

Knowledge objects

B.

Commands

C.

Lookups

D.

Macros