Exit demo SPLK-5001 Splunk Certified Cybersecurity Defense Analyst PDF format · free preview

Splunk SPLK-5001 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/splk-5001.html

Question 1
Single choice

Which of the following is not a component of the Splunk Security Content library (ESCU, SSE)?

A.

Dashboards

B.

Reports

C.

Correlation searches

D.

Validated architectures

Question 2
Single choice

An organization is using Risk-Based Alerting (RBA). During the past few days, a user account generated multiple risk observations.
Splunk refers to this account as what type of entity?

A.

Risk Factor

B.

Risk Index

C.

Risk Analysis

D.

Risk Object

Question 3
Single choice

A Cyber Threat Intelligence (CTI) team produces a report detailing a specific threat actor's typical behaviors and intent.
This would be an example of what type of intelligence?

A.

Operational

B.

Executive

C.

Tactical

D.

Strategic

Question 4
Single choice

Which field is automatically added to search results when assets are properly defined and enabled in Splunk Enterprise Security?

A.

asset_category

B.

src_ip

C.

src_category

D.

user

Question 5
Single choice

The following list contains examples of Tactics, Techniques, and Procedures (TTPs):

1. Exploiting a remote service

2. Lateral movement

3. Use EternalBlue to exploit a remote SMB server

In which order are they listed below?

A.

Tactic, Technique, Procedure

B.

Procedure, Technique, Tactic

C.

Technique, Tactic, Procedure

D.

Tactic, Procedure, Technique

Question 6
Single choice

What device typically sits at a network perimeter to detect command and control and other potentially suspicious traffic?

A.

Host-based firewall

B.

Web proxy

C.

Endpoint Detection and Response

D.

Intrusion Detection System

Question 7
Single choice

An analyst is not sure that all of the potential data sources at her company are being correctly or completely utilized by Splunk and Enterprise Security.

Which of the following might she suggest using, in order to perform an analysis of the data types available and some of their potential security uses?

A.

Splunk ITSI

B.

Security Essentials

C.

SOAR

D.

Splunk Intelligence Management

Question 8
Single choice

A Cyber Threat Intelligence (CTI) team delivers a briefing to the CISO detailing their view of the threat landscape the organization faces.
This is an example of what type of Threat Intelligence?

A.

Tactical

B.

Strategic

C.

Operational

D.

Executive

Question 9
Single choice

An analyst is examining the logs for a web application's login form. They see thousands of failed logon attempts using various usernames and passwords. Internet research indicates that these credentials may have been compiled by combining account information from several recent data breaches.

Which type of attack would this be an example of?

A.

Credential sniffing

B.

Password cracking

C.

Password spraying

D.

Credential stuffing

Question 10
Single choice

Which of the following is considered Personal Data under GDPR?

A.

The birth date of an unidentified user.

B.

An individual's address including their first and last name.

C.

The name of a deceased individual.

D.

A company's registration number.

Showing 10 of 66 questions · Unlock the full set