
パスできるSPLK-5001試験最速合格保証2026問題集!
SPLK-5001問題集完全版問題で試験学習ガイド
質問 # 11
Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?
- A. Risk Framework
- B. Notable Event Framework
- C. Threat Intelligence Framework
- D. Asset and Identity Framework
正解:A
質問 # 12
An analyst is examining the logs for a web application's login form. They see thousands of failed logon attempts using various usernames and passwords. Internet research indicates that these credentials may have been compiled by combining account information from several recent data breaches.
Which type of attack would this be an example of?
- A. Credential stuffing
- B. Password spraying
- C. Credential sniffing
- D. Password cracking
正解:A
質問 # 13
An analyst discovers malicious software present within the network. When tracing the origin of the software, the analyst discovers it is actually a part of a third-party vendor application that is used regularly by the organization. This is an example of what kind of threat?
- A. Third-Party Malware
- B. Account Takeover
- C. Ransomware
- D. Supply Chain Attack
正解:D
質問 # 14
An analyst is building a search to examine Windows XML Event Logs, but the initial search is not returning any extracted fields. Based on the above image, what is the most likely cause?
- A. The analyst does not have the proper role to search this data.
- B. The analyst is not in the Drooer Search Mode and should switch to Smart or Verbose.
- C. The analyst is searching newly indexed data that was improperly parsed.
- D. The analyst did not add the excract command to their search pipeline.
正解:D
質問 # 15
An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host. According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
- A. dest
- B. src_ip
- C. host
- D. src_nt_host
正解:B
質問 # 16
Which of the following is the primary benefit of using the CIM in Splunk?
- A. It improves the performance of search queries on raw data.
- B. It automatically detects and blocks cyber threats.
- C. It allows for easier correlation of data from different sources.
- D. It enables the use of advanced machine learning algorithms.
正解:C
質問 # 17
How are Notable Events configured in Splunk Enterprise Security?
- A. Via an Adaptive Response Action in a correlation search.
- B. Via an Adaptive Response Action in a regular search.
- C. During an investigation.
- D. As part of an audit.
正解:A
質問 # 18
Which of the following use cases is best suited to be a Splunk SOAR Playbook?
- A. Taking containment action on a compromised host
- B. Visualizing complex datasets.
- C. Creating persistent field extractions.
- D. Forming hypothesis for Threat Hunting
正解:A
質問 # 19
As an analyst, tracking unique users is a common occurrence. The Security Operations Center (SOC) manager requested a search with results in a table format to track the cumulative downloads by distinct IP address. Which example calculates the running total of distinct users over time?
- A. eventtype="download" | bin_time span=1d | stats values(clientip) as ipa dc(clientip) by _time | streamstats dc(ipa) as "Cumulative total"
- B. eventtype="download" | bin_time span=1d | stats values(clientip) as ipa dc(clientip) by user | table _time ipa
- C. eventtype="download" | bin_time span=1d | stats values(clientip) as ipa dc(clientip) by _time
- D. eventtype="download" | bin_time span=1d | table clientip _time user
正解:A
質問 # 20
The United States Department of Defense (DoD) requires all government contractors to provide adequate security safeguards referenced in National Institute of Standards and Technology (NIST) 800-171. All DoD contractors must continually reassess, monitor, and track compliance to be able to do business with the US government.
Which feature of Splunk Enterprise Security provides an analyst context for the correlation search mapping to the specific NIST guidelines?
- A. Framework mapping
- B. Moles
- C. Annotations
- D. Comments
正解:A
質問 # 21
What goal of an Advanced Persistent Threat (APT) group aims to disrupt or damage on behalf of a cause?
- A. Prestige
- B. Financial gain
- C. Cyber espionage
- D. Hacktivism
正解:D
質問 # 22
A Risk Rule generates events on Suspicious Cloud Share Activity and regularly contributes to confirmed incidents from Risk Notables. An analyst realizes the raw logs these events are generated from contain information which helps them determine what might be malicious.
What should they ask their engineer for to make their analysis easier?
- A. Create another detection for this information.
- B. Add this information to the risk message.
- C. Create a field extraction for this information.
- D. Allowlist more events based on this information.
正解:C
質問 # 23
In Splunk Enterprise Security, annotations can be added to enrich correlation search results with security framework mappings. Which of the following security frameworks is not available as a default annotation option?
- A. Lockheed Martin Cyber Kill Chain
- B. MITRE ATT&CK
- C. CIS
- D. OWASP Top 10
正解:D
質問 # 24
Which stage of continuous monitoring involves adding data, creating detections, and building drilldowns?
- A. Establish and Architect
- B. Respond and Review
- C. Implement and Collect
- D. Analyze and Report
正解:C
質問 # 25
Which of the following is not considered a type of default metadata in Splunk?
- A. Host name
- B. Source of data
- C. Event description
- D. Timestamps
正解:C
質問 # 26
......
Splunk SPLK-5001 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
Cybersecurity Defense Analyst無料認定試験資料は102問:https://www.passtest.jp/Splunk/SPLK-5001-shiken.html
リアルなSPLK-5001は100%カバーリアル試験問題を試そう:https://drive.google.com/open?id=1NWGd-AplDXCBsSCJXEL9sH9R9t33GNa2