Splunk SPLK-5002 - Splunk Certified Cybersecurity Defense Engineer Exam

Question #11 (Topic: Exam A)
When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?
A. This a Key Result Indicator, not a KPI. It is a metric that is measuring the results of the perimeter firewall's actions, not the performance of the firewall. B. Perimeter firewalls are exposed on the internet directly and thus subject to automated scanners and attack tools. C. The metric is too high level, it should be broken down by the type of block. For example, blocks of remote systems that have repeated failed connections to services that do not exist. D. Perimeter firewalls should be measured on both the number of connections that they permit as well as the number they block.
Answer: B
Question #12 (Topic: Exam A)
Which stash event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?
A. search_sid B. search_rid C. orig_sid D. orig_rid
Answer: A
Question #13 (Topic: Exam A)
An engineer needs to create a new report capturing the vendors and products that detect a particular CVE in their environment. How can they ensure that their search associated with the report only includes accelerated data?
A. Search for the vendor_product within the Vulnerabilities data model, using the | tstats command. B. Search for the cve within the Vulnerabilities data model, using | tstats grouped by vendor_product with summariesonly=true. C. Search for the vendor_product within the Updates data model, using the | tstats command. D. Search for the vendor_product within the Updates data model, using | tstats grouped by eve with summariesonly=true.
Answer: B
Question #14 (Topic: Exam A)
What field is used by default to direct data into CIM data model datasets?
A. sourcetype B. tag C. dataset D. source
Answer: B
Question #15 (Topic: Exam A)
An engineer receives a report that the "Traffic over time by action" dashboard is not populating. It has been confirmed that the relevant logs are being ingested properly and they are CIM compliant.
What other configuration may be missing?
A. The Performance data model is missing the network dataset. B. The Network Traffic data model should be accelerated. C. The Network Sessions data model has been deleted. D. The Network Sessions data model should be accelerated.
Answer: B
Download Exam
Page: 3 / 21
Total 102 questions