Advanced Threat Intelligence and AnalysisSecurity Data ManagementAdvanced Incident Response and ManagementAdvanced Automation and OrchestrationScaling Cybersecurity Defenses and DevSecOpsGovernance, Risk, and ComplianceMeasuring and Improving Security Program EffectivenessSecurity Capability Selection, Placement, Configuration
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
In a Risk-Based Alerting implementation using Splunk Enterprise Security, which option best defines a risk factor?
AA SOAR action that is drawn from annotations.
BA multiplier of risk that depends on the characteristics of the specific user or asset.
CA tool to enable risk data model acceleration.
DAn event that modifies risk based on the characteristics of the specific user or asset.
Consider this sequence of events:
4:00 GMT: Detection runs for the 3:30–4:00 interval.
4:30 GMT: Detection runs for the 4:00–4:30 interval.
4:35 GMT: Event 1 occurs on an endpoint.
4:45 GMT: Event 1 is indexed.
5:00 GMT: Detection runs for the 4:30–5:00 interval.
5:05 GMT: The Event 1 finding is added to ES with a 4:35 timestamp.
5:24 GMT: Event 2 occurs on an endpoint.
5:30 GMT: Detection runs for the 5:00–5:30 interval.
5:35 GMT: Event 2 is indexed.
6:00 GMT: Detection runs for the 5:30–6:00 interval.
What is wrong with the selected detection schedule, and how can it be resolved?
AThe time window for the detection is too large, causing duplicate alerts.
BThe logs are delayed so the detection time window needs to be increased.
CThe time window for the detection is too small, causing duplicate alerts.
DThe logs are delayed so the detection time window needs to be decreased.
An automation engineer for the Wonderland SOC has configured a new asset and receives an HTTP 403 response code. Which of the following could be the cause of this error code?
AThe asset endpoint requires a token not username and password.
BAsset credentials don't have adequate permissions.
CThe endpoint that the asset is configured for does not exist.
DEither asset username or password are incorrect.
Which Enterprise Security components enrich the Risk Framework?
Which tool can help establish a baseline of the data sources in a given Splunk environment?
AEnterprise Security Content Update
BEnterprise Security Data Library
CSplunk Security Essentials Analytic Stories
DSplunk Security Essentials Data Inventory
An engineer observes that a detection is producing multiple findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of findings (notables) generated?
ACorrelation search priority
BAdaptive response actions
CAdaptive risk modifier
DCorrelation search throttling
An engineer is reviewing a correlation search during a detection review and observes that it is configured as follows:
Which of the following is true about this configuration?
AThere could be missing data as the search schedule is not ingesting data properly.
BThere could be missing findings as the search frequency and time range are improperly configured.
CThe search will run as prescribed without issue every 30 minutes.
DThe risk modifiers should be adjusted for an hour of data.
Which of the following detections would use a high number of events with Windows Event Code 4740, grouped by user, to identify suspicious behavior?
ADetect Excessive User Logins
BDetect Excessive AWS Security Scanning
CDetect Excessive Network Connections
DDetect Excessive User Account Lockouts
Which Splunk feature lets you make SPL searches shorter and reusable by inserting it into search strings?
AMacros
BLookups
CCommands
DKnowledge objects
A cyber defense engineer helps maintain a secure SOAR Cloud configuration. Which network-security statement about SOAR Cloud is correct?
AThe Automation Broker initiates an inbound SSL connection to Splunk Cloud, and also initiates an outbound connection to the managed endpoints.
BSplunk Cloud initiates an outbound SSL connection to both the Automation Broker and managed endpoints.
CThe Automation Broker initiates an outbound SSL connection to Splunk Cloud, and also initiates an outbound connection to the managed endpoints.
DThe Automation Broker initiates an outbound SSL connection to Splunk Cloud, and the managed endpoint initiates an outbound connection to the Automation Broker.
If a correlation search cannot run at the configured time, which scheduling option should an engineer select to ensure there are no gaps in backfilled data?
ADefault
BContinuous
CReal-time
DAuto
Within Splunk's Common Information Model (CIM), which constraint makes sure events from different data sources appear in the relevant data model?
Ahosts
Bfield names
Csources
Dtags
Which search command generated the result shown below?
Ametadata
Bdatatype
Ccim
Ddatamodel
An engineer needs to track and report on every authentication to corporate assets, while prioritizing critical assets without substantially increasing the number of generated findings (notable events). What process could accomplish this goal?
ADetermine a general risk rule for all access attempts to all assets, and then increase the Risk Factor for critical assets.
BDecrease the risk score of non-critical assets in all existing detections.
CAdd all access attempts to the Risk Index, and increase the Criticality of the critical assets.
DAdd the critical assets to the risk data model.
An engineer is told that the "Traffic over time by action" dashboard is not populating. It has been confirmed that the applicable logs are being ingested correctly and are CIM compliant.
What other configuration might be missing?
AThe Performance data model is missing the network dataset.
BThe Network Traffic data model should be accelerated.
CThe Network Sessions data model has been deleted.
DThe Network Sessions data model should be accelerated.
Which of the following should serve as the primary reference when designing a new playbook in Splunk SOAR?
AExisting investigation actions
BMITRE ATT&CK® framework
CExisting Standard Operating Procedure
DCIS Framework
An engineer must create a new report that captures the vendors and products detecting a particular CVE in their environment. How can they make sure the search associated with the report includes only accelerated data?
ASearch for the vendor_product within the Vulnerabilities data model, using the | tstats command.
BSearch for the cve within the Vulnerabilities data model, using | tstats grouped by vendor_product with summariesonly=true.
CSearch for the vendor_product within the Updates data model, using the | tstats command.
DSearch for the vendor_product within the Updates data model, using | tstats grouped by eve with summariesonly=true.
Using a Standard Operating Procedure (SOP) is an effective way to ensure analysts respond to generated findings consistently and analytically. Where within the Notable Adaptive Response Action is the best location to include a link to an SOP?
ANext Steps
BDescription
CUseful Links
DRecommended Actions
A SOC's Incident Response Standard Operating Procedure (SOP) requires that any phishing emails containing files be detonated in Splunk Attack Analyzer for evaluation. Which of the following can an engineer implement to improve efficiency through automation?
AAutomatically send all findings containing the tag "phishing" to create an email notification for the SOC.
BUse a SOAR playbook to submit the email to PhishTank, which will automatically handle the Splunk Attack Analyzer submission, and make this information available to an assigned analyst.
CAutomatically assign findings containing the tag "phishing" to analysts to speed up the start of data collection steps and reduce the time to disposition for the finding.
DUse a SOAR playbook to handle the Splunk Attack Analyzer submission and data collection steps, and make this information available to an assigned analyst.
An EDR tool has recently been purchased and must be integrated with the existing Splunk SOAR playbooks. Which actions are commonly associated with this kind of asset?
ABlock device, remove email, detonate URL, get indicator
BBlock URL, block subdomain, quarantine device, get indicator, detonate URL
CBlock hash, block process, quarantine device, get indicator
DBlock hash, reset user password, quarantine device, get indicator
Community Discussion