Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Questions 4

Which of the following is a reason to utilize ES risk framework as a part of detection building?

Options:

A.

Help accelerate the run time of detections, allowing a faster mean time to detection.

B.

Create a feedback loop into threat intelligence to identify potential insider threats.

C.

Help prioritize security findings based on their potential business impact.

D.

Simplify SOAR automation and remediation, lowering the mean time to recover.

Buy Now
Questions 5

The SOC notices over the course of an investigation there are numerous logs similar to the following:

UDP: query: reallybad.c2.com IN A response: SERVFAIL

What detection should be created to alert on this behavior for the future?

Options:

A.

Excessive DNS Failures

B.

Excessive Authentication Failures

C.

Excessive Network Failures

D.

Excessive Endpoint Failures

Buy Now
Questions 6

When creating a new playbook to be called directly from Mission Control or Enterprise Security, which type of playbook must be used?

Options:

A.

Input

B.

Automation

C.

Process

D.

Response

Buy Now
Questions 7

An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?

Options:

A.

Correlation search throttling

B.

Correlation search priority

C.

Adaptive risk modifier

D.

Adaptive response actions

Buy Now
Questions 8

When using SOAR to automate a response with a zero trust approach, which of the following represents a valid order of operations?

Options:

A.

Contain, triage initial incident, identify scope, remediate and/or restore

B.

Triage initial incident, identify scope, contain, remediate and/or restore

C.

Identify, scope, remediate and/or restore, triage

D.

Observe, orient, decide, act

Buy Now
Questions 9

In a contextualization playbook, a URL is transmitted to a sandbox for examination and disposition recommendation. What underlying HTTP method is used to transmit this data to the sandbox?

Options:

A.

GET

B.

POST

C.

STOR

D.

PUT

Buy Now
Questions 10

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?

Options:

A.

Threat Intelligence

B.

Data models

C.

Analytic Stories

D.

Assets & Identities framework

Buy Now
Questions 11

Which of the following can process data from configured containers using an automated sequence of actions?

Options:

A.

Cases

B.

Workbooks

C.

Containers

D.

Playbooks

Buy Now
Questions 12

When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?

Options:

A.

Search Splunk Enterprise Security for similar or duplicate events based on the threat_object field in a risk notable.

B.

Search Splunk Enterprise Security for all related events based on key fields in a notable and select how to process the results to decide which events to merge into the current investigation.

C.

Search Splunk Enterprise Security for similar or duplicate events based on the risk_object field in a risk notable.

D.

Search Splunk Enterprise Security for all related events based on key fields in a risk notable and select how to process the results to decide which events to merge into the current investigation.

Buy Now
Questions 13

An engineer has discovered that an acquired company uses a duplicate IP address space. Which feature of the asset and identity framework could be turned on that would allow for the separation of company IP address ranges within a lookup?

Options:

A.

Entity Definitions

B.

Asset Classes

C.

Entity Zones

D.

Asset Annotations

Buy Now
Questions 14

The Director of Security would like to understand the operational efficiency of the SOC analysts at a high level. What is a metric that can be used to determine their efficiency?

Options:

A.

MTTI

B.

MTBR

C.

MTTR

D.

MTTD

Buy Now
Questions 15

How can an engineer verify if results will return for a potential detection based on historical events within the organization?

Options:

A.

Run the detection with appropriate earliest and latest constraints covering the historical events.

B.

Run the detection against production data only within the default current time range.

C.

Run the detection using an inappropriate time constraint that does not cover the historical events.

D.

Run the detection in Splunk Attack Range against the latest Atomic Red Team injections.

Buy Now
Questions 16

Which search command was used to generate the result in the image below?

Options:

A.

metadata

B.

datatype

C.

cim

D.

datamodel

Buy Now
Questions 17

When building detections using the Authentication Data Model, which values are recommended for use against the action field?

Options:

A.

allowed, blocked, processing, error

B.

success, failure, pending, error

C.

allowed, blocked, inactivity, error

D.

success, denied, pending, error

Buy Now
Questions 18

Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?

Options:

A.

Existing investigation actions

B.

MITRE ATT & CK® framework

C.

Existing Standard Operating Procedure

D.

CIS Framework

Buy Now
Questions 19

In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?

Options:

A.

A multiplier of risk that depends on the characteristics of the specific user or asset.

B.

An event that modifies risk based on the characteristics of the specific user or asset.

C.

A tool to enable risk data model acceleration.

D.

A SOAR action that is drawn from annotations.

Buy Now
Questions 20

Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?

Options:

A.

Detect Excessive AWS Security Scanning

B.

Detect Excessive User Account Lockouts

C.

Detect Excessive User Logins

D.

Detect Excessive Network Connections

Buy Now
Questions 21

An engineer wants to track and report on all authentication to corporate assets and wants to prioritize critical assets without significantly increasing the number of findings created. What process could be used to accomplish this goal?

Options:

A.

Decrease the risk score of non-critical assets in all existing detections.

B.

Add all access attempts to the Risk Index and increase criticality of critical assets.

C.

Add the critical assets to the risk data model.

D.

Determine a general risk rule for all access attempts to all assets, and then increase the Risk Factor for critical assets.

Buy Now
Questions 22

Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)

Options:

A.

Regular updates based on feedback

B.

Focusing solely on high-risk scenarios

C.

Collaborating with cross-functional teams

D.

Including detailed step-by-step instructions

E.

Excluding historical incident data

Buy Now
Questions 23

Which action improves the effectiveness of notable events in Enterprise Security?

Options:

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Buy Now
Questions 24

One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide context options through the use of which of the following settings?

Options:

A.

Correlation Search Name

B.

Risk Object Name

C.

Risk Analysis Adaptive Response Action

D.

Drill-down search

Buy Now
Questions 25

MITRE D3FEND® is designed to complement MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?

Options:

A.

Harden, Detect, Isolate, Disrupt, Evict

B.

Harden, Detect, Enrich, Define, Eradicate

C.

Harden, Detect, Isolate, Deceive, Evict

D.

Harden, Detect, Exhaust, Deceive, Eradicate

Buy Now
Questions 26

Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?

Options:

A.

Rendering a verdict

B.

Triage

C.

Containment

D.

Remediation

Buy Now
Questions 27

The threat-hunting team has identified suspicious activity. An analyst manually creates a notable event using an event action to track the activity. How should a detection engineer ensure this activity automatically produces findings in the future?

Options:

A.

Create a SOAR playbook to identify events matching the activity and assign an urgency.

B.

Create a correlation search to produce notable events for the activity.

C.

Create a SOAR playbook to assign risk modifiers for events matching the activity.

D.

Create a risk modifier for events matching the activity.

Buy Now
Questions 28

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

Options:

A.

user_id

B.

user

C.

action

D.

identity

Buy Now
Questions 29

Consider the following series of events:

4:00 GMT Detection runs for interval 3:30–4:00

4:30 GMT Detection runs for interval 4:00–4:30

4:35 GMT Event 1 occurs on an endpoint

4:45 GMT Event 1 is indexed

5:00 GMT Detection runs for interval 4:30–5:00

5:05 GMT Event 1 finding is added to ES with timestamp 4:35

5:24 GMT Event 2 occurs on an endpoint

5:30 GMT Detection runs for interval 5:00–5:30

5:35 GMT Event 2 is indexed

6:00 GMT Detection runs for interval 5:30–6:00

What is the problem with the detection schedule chosen and how can it be solved?

Options:

A.

The logs are delayed so the detection time window needs to be decreased.

B.

The time window for the detection is too small, causing duplicate alerts.

C.

The time window for the detection is too large, causing duplicate alerts.

D.

The logs are delayed so the detection time window needs to be increased.

Buy Now
Questions 30

Which features are crucial for validating integrations in Splunk SOAR? (Choose three)

Options:

A.

Testing API connectivity

B.

Monitoring data ingestion rates

C.

Verifying authentication methods

D.

Evaluating automated action performance

E.

Increasing indexer capacity

Buy Now
Questions 31

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

Options:

A.

service_intel

B.

http_intel

C.

certificate_intel

D.

ip_intel

Buy Now
Exam Code: SPLK-5002
Exam Name: Splunk Certified Cybersecurity Defense Engineer
Last Update: Oct 4, 2026
Questions: 105
SPLK-5002 pdf

SPLK-5002 PDF

$21.25  $84.99
SPLK-5002 Engine

SPLK-5002 Testing Engine

$25  $99.99
SPLK-5002 PDF + Engine

SPLK-5002 PDF + Testing Engine

$33.75  $134.99