Which of the following is a reason to utilize ES risk framework as a part of detection building?
The SOC notices over the course of an investigation there are numerous logs similar to the following:
UDP: query: reallybad.c2.com IN A response: SERVFAIL
What detection should be created to alert on this behavior for the future?
When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?
An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?
When using SOAR to automate a response with a zero trust approach, which of the following represents a valid order of operations?
In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?
During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?
Which of the following can process data from configured containers using an automated sequence of actions?
When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?
An engineer has discovered that an acquired company uses a duplicate IP address space. Which feature of the asset and identity framework could be turned on that would allow for the separation of company IP address ranges within a lookup?
The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?
How can an engineer verify if results will return for a potential detection based on historical events within the organization?
When building detections using the Authentication Data Model, which values are recommended for use against the action field?
Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?
In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?
Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
An engineer wants to track and report on all authentication to corporate assets and wants to prioritize critical assets without significantly increasing the number of findings created. What process could be used to accomplish this goal?
Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)
Which action improves the effectiveness of notable events in Enterprise Security?
One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide context options through the use of which of the following settings?
MITRE D3FEND® is designed to complement MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?
Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?
The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer ensure this activity automatically produces findings in the future?
When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?
Consider the following series of events:
4:00 GMT Detection runs for interval 3:30–4:00
4:30 GMT Detection runs for interval 4:00–4:30
4:35 GMT Event 1 occurs on an endpoint
4:45 GMT Event 1 is indexed
5:00 GMT Detection runs for interval 4:30–5:00
5:05 GMT Event 1 finding is added to ES with timestamp 4:35
5:24 GMT Event 2 occurs on an endpoint
5:30 GMT Detection runs for interval 5:00–5:30
5:35 GMT Event 2 is indexed
6:00 GMT Detection runs for interval 5:30–6:00
What is the problem with the detection schedule chosen and how can it be solved?
Which features are crucial for validating integrations in Splunk SOAR? (Choose three)
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?