Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Splunk SPLK-5002 - Splunk Certified Cybersecurity Defense Engineer

Page: 1 / 3
Total 83 questions

A security analyst wants to validate whether a newly deployed SOAR playbook is performing as expected.

Whatsteps should they take?

A.

Test the playbook using simulated incidents

B.

Monitor the playbook's actions in real-time environments

C.

Automate all tasks within the playbook immediately

D.

Compare the playbook to existing incident response workflows

What methods improve the efficiency of Splunk’s automation capabilities? (Choose three)

A.

Using modular inputs

B.

Optimizing correlation search queries

C.

Leveraging saved search acceleration

D.

Implementing low-latency indexing

E.

Employing prebuilt SOAR playbooks

During an incident, a correlation search generates several notable events related to failed logins. The engineer notices the events are from test accounts.

Whatshould be done to address this?

A.

Disable the correlation search for test accounts.

B.

Apply filtering to exclude test accounts from the search results.

C.

Lower the search threshold for failed logins.

D.

Suppress all notable events temporarily.

Which sourcetype configurations affect data ingestion?(Choosethree)

A.

Event breaking rules

B.

Timestamp extraction

C.

Data retention policies

D.

Line merging rules

How can Splunk engineers monitor indexing performance effectively?(Choosetwo)

A.

Use the Monitoring Console.

B.

Create correlation searches on indexed data.

C.

Enable detailed event logging for indexers.

D.

Track indexer queue size and throughput.

Which report type is most suitable for monitoring the success of a phishing campaign detection program?

A.

Weekly incident trend reports

B.

Real-time notable event dashboards

C.

Risk score-based summary reports

D.

SLA compliance reports

What are key benefits of using summary indexing in Splunk? (Choose two)

A.

Reduces storage space required for raw data

B.

Improves search performance on aggregated data

C.

Provides automatic field extraction during indexing

D.

Increases data retention period

What Splunk process ensures that duplicate data is not indexed?

A.

Data deduplication

B.

Metadata tagging

C.

Indexer clustering

D.

Event parsing

Which REST API actions can Splunk perform to optimize automation workflows?(Choosetwo)

A.

POST for creating new data entries

B.

DELETE for archiving historical data

C.

GET for retrieving search results

D.

PUT for updating index configurations

A company wants to implement risk-based detection for privileged account activities.

Whatshould they configure first?

A.

Asset and identity information for privileged accounts

B.

Correlation searches with low thresholds

C.

Event sampling for raw data

D.

Automated dashboards for all accounts