Splunk SPLK-5003 - Splunk Certified Cybersecurity Defense Architect Exam
Page: 3 / 24
Total 120 questions
Question #11 (Topic: Exam A)
Emma is a security architect helping migrate her organization’s on-premises SIEM to a newer version of the same SIEM running in a cloud provider. The newer version includes enhanced capabilities for writing detection content. The detection engineering team has built hundreds of rules in the on-premises SIEM over the years.
As Emma starts planning for the migration, what should she do about moving the detection rules to the new platform?
As Emma starts planning for the migration, what should she do about moving the detection rules to the new platform?
A. Export half of the rules from the SIEM and manually convert them.
B. Nothing, the newer version’s default detection content will cover the organization’s needs.
C. Export all of the rules from the SIEM in Sigma format and import them into the new platform.
D. Review which rules are still relevant to the organization’s threat models to prioritize for migration.
Answer: D
Question #12 (Topic: Exam A)
What is a SBOM?
A. A comprehensive list of components, libraries, and dependencies
B. A comprehensive list of search heads, indexers, and forwarders
C. A comprehensive list of indicators, detections, and alerts
D. A comprehensive list of searches, macros, and reports
Answer: A
Question #13 (Topic: Exam A)
Bocklava, Inc. is looking to launch their Software as a Service in an environment that is accredited against a specific control framework (i.e. PCI, ISO).
What is the most effective way to ensure the appropriate controls of this environment are properly funded and implemented?
What is the most effective way to ensure the appropriate controls of this environment are properly funded and implemented?
A. Create a business case for the environment to meet all required controls.
B. Hire a red team assessment to identify gaps.
C. Align the cost of the controls to the revenue generated by the new environment.
D. Ensure all requirements are entered in the ticketing system.
Answer: A
Question #14 (Topic: Exam A)
Of the following options, which is the best approach to implementing an effective business continuity plan?
A. Develop the plan based on IT infrastructure.
B. Create a one-time plan.
C. Store data backups offsite.
D. Define recovery objectives and regularly test the plan.
Answer: D
Question #15 (Topic: Exam A)
An alert has generated for a malicious file tied to a previously unknown malware.
In order to protect the integrity of the investigation, how can the response team automate collection of evidence?
In order to protect the integrity of the investigation, how can the response team automate collection of evidence?
A. Pull the file from the system and detonate in a sandbox.
B. Pull the file directly from the system and store in a vault.
C. Send the Indicators of Compromise to the law enforcement agency.
D. Quarantine and shut down the system.
Answer: B