Splunk SPLK-5001 - Splunk Certified Cybersecurity Defense Analyst Exam

Question #11 (Topic: Exam A)
A Risk Rule generates events on Suspicious Cloud Share Activity and regularly contributes to confirmed incidents from Risk Notables. An analyst realizes the raw logs these events are generated from contain information which helps them determine what might be malicious.
What should they ask their engineer for to make their analysis easier?
A. Create a field extraction for this information. B. Add this information to the risk_message. C. Create another detection for this information. D. Allowlist more events based on this information.
Answer: A
Question #12 (Topic: Exam A)
What device typically sits at a network perimeter to detect command and control and other potentially suspicious traffic?
A. Host-based firewall B. Web proxy C. Endpoint Detection and Response D. Intrusion Detection System
Answer: D
Question #13 (Topic: Exam A)
Upon investigating a report of a web server becoming unavailable, the security analyst finds that the web server’s access log has the same log entry millions of times:
147.186.119.200 - - [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733
What kind of attack is occurring?
A. Denial of Service Attack B. Distributed Denial of Service Attack C. Cross-Site Scripting Attack D. Database Injection Attack
Answer: A
Question #14 (Topic: Exam A)
According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?
A. Domain names B. TTPs C. Network/Host artifacts D. Hash values
Answer: D
Question #15 (Topic: Exam A)
An analysis of an organization’s security posture determined that a particular asset is at risk and a new process or solution should be implemented to protect it. Typically, who would be in charge of implementing the new process or solution that was selected?
A. Security Architect B. SOC Manager C. Security Engineer D. Security Analyst
Answer: C
Download Exam
Page: 3 / 27
Total 131 questions