Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Splunk SPLK-5002 Practice Exam with Questions & Answers | Set: 3

Questions 21

Based on a recent red team exercise, an organization is highly concerned about pass-the-hash attacks, especially including tools like Empire. Which EventCode associated with PowerShell Script Block Logging would be used to detect this activity?

Options:
A.

EventCode=4104

B.

EventCode=4126

C.

EventCode=4624

D.

EventCode=4168

Splunk SPLK-5002 Premium Access
Questions 22

In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?

Options:
A.

GET

B.

POST

C.

STOR

D.

PUT

Questions 23

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

Options:
A.

A raw-event search followed by aggregation.

B.

A non-index-grouped metadata search.

C.

An index=* event search followed by stats.

D.

A tstats search returning sourcetypes and grouping them by index.

Questions 24

Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?

Options:
A.

Rendering a verdict

B.

Triage

C.

Containment

D.

Remediation

Questions 25

Which tool can help identify known tactics, techniques, and procedures that a threat group is most likely to use when targeting a financial organization?

Options:
A.

The MITRE ATT & CK® Posture panel within Mission Control ' s Incident Review page

B.

The MITRE ATT & CK® matrix ' s industry heatmap in Splunk Security Essentials

C.

The Lockheed Martin Cyber Kill Chain® Posture panel within Enterprise Security ' s Incident Review page

D.

Splunk Threat Intelligence Management

Questions 26

Which features are crucial for validating integrations in Splunk SOAR? (Choose three)

Options:
A.

Testing API connectivity

B.

Monitoring data ingestion rates

C.

Verifying authentication methods

D.

Evaluating automated action performance

E.

Increasing indexer capacity

Questions 27

If a correlation search cannot be run at the configured time, which scheduling option should an engineer use to ensure there are no backfill gaps in data?

Options:
A.

Default

B.

Continuous

C.

Real-time

D.

Auto

Questions 28

Which of the following is a reason to utilize ES risk framework as a part of detection building?

Options:
A.

Help accelerate the run time of detections, allowing a faster mean time to detection.

B.

Create a feedback loop into threat intelligence to identify potential insider threats.

C.

Help prioritize security findings based on their potential business impact.

D.

Simplify SOAR automation and remediation, lowering the mean time to recover.

Questions 29

Consider the following series of events:

4:00 GMT Detection runs for interval 3:30–4:00

4:30 GMT Detection runs for interval 4:00–4:30

4:35 GMT Event 1 occurs on an endpoint

4:45 GMT Event 1 is indexed

5:00 GMT Detection runs for interval 4:30–5:00

5:05 GMT Event 1 finding is added to ES with timestamp 4:35

5:24 GMT Event 2 occurs on an endpoint

5:30 GMT Detection runs for interval 5:00–5:30

5:35 GMT Event 2 is indexed

6:00 GMT Detection runs for interval 5:30–6:00

What is the problem with the detection schedule chosen and how can it be solved?

Options:
A.

The logs are delayed so the detection time window needs to be decreased.

B.

The time window for the detection is too small, causing duplicate alerts.

C.

The time window for the detection is too large, causing duplicate alerts.

D.

The logs are delayed so the detection time window needs to be increased.

Questions 30

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

Options:
A.

Parameters

B.

Payload

C.

Headers

D.

KV Elements