Splunk Certified Cybersecurity Defense Analyst SPLK-5001 Exam Questions

Page: 1 / 14
Total 99 questions
Question 1

What is the term for a model of normal network activity used to detect deviations?



Answer : A


Question 2

What is the first phase of the Continuous Monitoring cycle?



Answer : B


Question 3

A Risk Notable Event has been triggered in Splunk Enterprise Security, an analyst investigates the alert, and determines it is a false positive. What metric would be used to define the time between alert creation and close of the event?



Answer : A


Question 4

Which dashboard in Enterprise Security would an analyst use to generate a report on users who are currently on a watchlist?



Answer : D


Question 5

Rotating encryption keys after a security incident is most closely linked to which security concept?



Answer : A


Question 6

While the top command is utilized to find the most common values contained within a field, a Cyber Defense Analyst hunts for anomalies. Which of the following Splunk commands returns the least common values?



Answer : C


Question 7

What Splunk feature would enable enriching public IP addresses with ASN and owner information?



Answer : B


Page:    1 / 14   
Total 99 questions