Splunk Certified Cybersecurity Defense Engineer - SPLK-5002 模擬練習
Which of the following macro values will exclude all of the company networks if it is called from the following search?
index=firewall sourcetype=pan:traffic NOT "company_networks"
index=firewall sourcetype=pan:traffic NOT "company_networks"
正解: A
解説: (PassTest メンバーにのみ表示されます)
The SOC manager has a desire to measure mean time to acknowledge findings (notable events) in order to meet a desired service level objective. Which two fields can be used to measure this metric?
正解: A
解説: (PassTest メンバーにのみ表示されます)
An EDR tool was recently purchased and needs to be integrated into existing Splunk SOAR playbooks. Which actions are typically associated with this type of asset?
正解: D
解説: (PassTest メンバーにのみ表示されます)
What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?
正解: D
解説: (PassTest メンバーにのみ表示されます)
Which of the following should an engineer do as they evaluate their Threat Detection and Incident Response lifecycle?
正解: C
解説: (PassTest メンバーにのみ表示されます)
When building detections using the Authentication Data Model, which values are recommended for use against the actions field?
正解: B
解説: (PassTest メンバーにのみ表示されます)
Which Enterprise Security components provide enrichment to the Risk Framework?
正解: B
解説: (PassTest メンバーにのみ表示されます)
A Splunk administrator needs to integrate a third-party vulnerability management tool to automate remediation workflows. What is the most efficient first step?
正解: B
解説: (PassTest メンバーにのみ表示されます)