Splunk SPLK-5002 - Splunk Certified Cybersecurity Defense Engineer
An engineer has been asked to build a new dashboard after an increase in login failures across the organization ' s Microsoft Azure domain. They need to construct a search to only display failed logins for their Azure Active Directory users and create a visualization that will help quickly identify failed logins that originate outside of North America. Which search and visualization type combination will achieve this?
Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they ' ve been utilizing for testing a detection named TestSearchDevelopment?
What is a key feature of effective security reports for stakeholders?
Based on a recent red team exercise, an organization is highly concerned about pass-the-hash attacks, especially including tools like Empire. Which EventCode associated with PowerShell Script Block Logging would be used to detect this activity?
Which field in the risk index is used to describe the activity within a finding?
Which syntax is correct to create two new rows on an existing threat intelligence collection?
Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?
An engineer wants to track and report on all authentication to corporate assets and wants to prioritize critical assets without significantly increasing the number of findings created. What process could be used to accomplish this goal?
Which of the following actions will allow access to a list of alert actions via the API?
If a correlation search cannot be run at the configured time, which scheduling option should an engineer use to ensure there are no backfill gaps in data?
