ExamDumpster

Free SPLK-5002 sample questions

Real questions from the Splunk Certified Cybersecurity Defense Engineer practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A Security Operations Center (SOC) is onboarding logs from a custom legacy firewall. The raw logs contain the action 'permit' or 'block', but the Splunk Common Information Model (CIM) requires the field 'action' to contain 'allowed' or 'blocked'. Which configuration method should the engineer use to normalize this data efficiently without altering the raw data?

Question 2Choose one

An engineer is troubleshooting a correlation search that utilizes the `tstats` command against a data model. The search is returning zero results despite raw data being present in the index. The data model acceleration summary shows as 100% complete. Which of the following is the most likely cause for the missing results?

Question 3Choose one

A Defense Engineer needs to implement a Risk-Based Alerting (RBA) strategy. They want to assign risk scores to users based on observed suspicious behaviors without triggering an immediate alert for every single event. Which type of correlation search should be configured to accomplish this?

Question 4Choose one

Review the following Mermaid diagram representing a Risk-Based Alerting (RBA) workflow: flowchart LR A[Raw Events] --> B{Correlation Search} B -->|Match| C[Risk Analysis Action] C --> D[Risk Index] D --> E{Risk Incident Rule} E -->|Threshold Met| F[Notable Event] At which stage in this workflow are 'Risk Modifiers' applied to the Risk Object?

Question 5Choose 2

A Splunk SOAR engineer is designing a playbook to handle phishing investigations. The playbook needs to extract all URLs from the email body and then check each URL against a reputation service. Which two playbook blocks are essential to achieve this workflow? (Select TWO)

Question 6Choose one

When integrating Splunk Enterprise Security (ES) with Splunk SOAR, an administrator wants to ensure that when a Notable Event's status is changed to 'Closed' in ES, the corresponding container in SOAR is also closed automatically. Which feature must be configured to enable this synchronization?

Question 7Choose one

A detection engineer is reviewing the efficacy of a specific correlation search. They notice that the search generates a high volume of alerts for a specific administrative subnet (10.10.5.0/24) performing legitimate scanning activities. What is the most effective way to suppress these specific alerts without disabling the detection for the rest of the network?

Question 8Choose one

True or False: In Splunk Enterprise Security, the Asset and Identity frameworks can automatically enrich notable events with departmental information, but they cannot effectively prioritize alerts based on the 'criticality' field of an asset.

Question 9Choose one

A security manager requires a monthly report detailing the 'Mean Time to Detect' (MTTD) and 'Mean Time to Respond' (MTTR) for the SOC. Which Splunk Enterprise Security dashboard provides these metrics out-of-the-box?

Question 10Choose one

You are creating a new correlation search to detect 'Brute Force Access' attempts. You want to ensure that if the search runs every 5 minutes and detects an attack, it creates a Notable Event, but does NOT create another duplicate event for the same user and destination for at least 1 hour. Which configuration setting handles this requirement?

10 more free samples are waiting

Create a free account to unlock the whole SPLK-5002 sample bank, or get full access to all 250 practice questions in the simulator.

Create account