Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Splunk Certified Cybersecurity Defense Analyst SPLK-5001 Exam Questions

Page: 1 / 10 Total 99 questions

Want more questions? Get Premium Access.

Question 1

Which of the following use cases is best suited to be a Splunk SOAR Playbook?

Correct Answer: D. Taking containment action on a compromised host

Question 2

Which of the following is considered Personal Data under GDPR?

Correct Answer: B. An individual's address including their first and last name.

Question 3

An analysis of an organization's security posture determined that a particular asset is at risk and a new process or solution should be implemented to protect it. Typically, who would be in charge of implementing the new process or solution that was selected?

Correct Answer: C. Security Engineer

Question 4

There are different metrics that can be used to provide insights into SOC operations. If Mean Time to Respond is defined as the total time it takes for an Analyst to disposition an event, what is the typical starting point for calculating this metric for a particular event?

Correct Answer: C. When a Notable Event is triggered.

Question 5

Which of the following is the primary benefit of using the CIM in Splunk?

Correct Answer: A. It allows for easier correlation of data from different sources.

Question 6

While testing the dynamic removal of credit card numbers, an analyst lands on using therexcommand. What mode needs to be set to in order to replace the defined values with X?

| makeresults

| eval ccnumber="511388720478619733"

| rex field=ccnumber mode=???"s/(\d{4}-){3)/XXXX-XXXX-XXXX-/g"

Please assume that the aboverexcommand is correctly written.

Correct Answer: A. sed

Question 7

The United States Department of Defense (DoD) requires all government contractors to provide adequate security safeguards referenced in National Institute of Standards and Technology (NIST) 800-171. All DoD contractors must continually reassess, monitor, and track compliance to be able to do business with the US government.

Which feature of Splunk Enterprise Security provides an analyst context for the correlation search mapping to the specific NIST guidelines?

Correct Answer: D. Framework mapping

Question 8

An analyst is attempting to investigate a Notable Event within Enterprise Security. Through the course of their investigation they determined that the logs and artifacts needed to investigate the alert are not available.

What event disposition should the analyst assign to the Notable Event?

Correct Answer: D. Other, since a security engineer needs to ingest the required logs.

Question 9

An analyst is looking at Web Server logs, and sees the following entry as the last web request that a server processed before unexpectedly shutting down:

[51.125.121.100 - [28/01/2006:10:27:10 -0300] "POST /cgi-bin/shurdown/ HTTP/1.0" 200 3304]

What kind of attack is most likely occurring?

Correct Answer: C. Denial of service attack.

Question 10

An analyst discovers malicious software present within the network. When tracing the origin of the software, the analyst discovers it is actually a part of a third-party vendor application that is used regularly by the organization. This is an example of what kind of threat?

Correct Answer: B. Supply Chain Attack