Pre-Winter Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Questions and Answers

Questions 4

Which of the following can process data from configured containers using an automated sequence of actions?

Options:

A.

Cases

B.

Workbooks

C.

Containers

D.

Playbooks

Buy Now
Questions 5

An engineer notices that a detection is creating multiple Findings (notables) for the same potential incident. Which setting can be adjusted to reduce the number of generated findings (notables)?

Options:

A.

Correlation search throttling

B.

Correlation search priority

C.

Adaptive risk modifier

D.

Adaptive response actions

Buy Now
Questions 6

What is one method used in ESCU content to calculate a risk score when creating a detection that uses the Risk Analysis adaptive response action?

Options:

A.

Risk Score = (Impact × Confidence / 100)

B.

Risk Score = (Risk Object Severity × Confidence / 100)

C.

Risk Score = (Risk Object Priority × Confidence / 100)

D.

Risk Score = (Impact × Priority / 100)

Buy Now
Questions 7

What is the primary purpose of data indexing in Splunk?

Options:

A.

To ensure data normalization

B.

To store raw data and enable fast search capabilities

C.

To secure data from unauthorized access

D.

To visualize data using dashboards

Buy Now
Questions 8

Which phase of the incident response lifecycle would cause the least amount of friction when replacing manual steps with automation?

Options:

A.

Rendering a verdict

B.

Triage

C.

Containment

D.

Remediation

Buy Now
Questions 9

Which REST call will show a list of alerts with their specific commands, app, and title?

Options:

A.

| rest /servicesNS/admin/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

B.

| rest /servicesNS/user/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

C.

| rest /servicesNs/admin/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

D.

| rest /servicesNS/user/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

Buy Now
Questions 10

An engineer adds a custom event status of ' Testing ' and accidentally makes it the new default status. Their SOC calculates some metrics based on Notable status change sequences, starting from the old default status of ' New ' . Which metrics can be affected by this mistake?

Options:

A.

Mean Time to Respond, Mean Time to Resolve

B.

No metrics are impacted

C.

Mean Time to Triage, Dwell Time

D.

Mean Time to Resolve, Dwell Time

Buy Now
Questions 11

An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?

Options:

A.

The endpoint that the asset is configured for does not exist.

B.

Either the asset username or password is incorrect.

C.

The asset endpoint requires a token rather than a username and password.

D.

Asset credentials do not have adequate permissions.

Buy Now
Questions 12

The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?

Options:

A.

Workbooks

B.

Events

C.

Cases

D.

Incidents

Buy Now
Questions 13

Which field in the risk index is used to describe the activity within a finding?

Options:

A.

risk_message

B.

risk_description

C.

risk_object

D.

risk_reason

Buy Now
Questions 14

Which of the following actions will allow access to a list of alert actions via the API?

Options:

A.

| rest /services/alerts/adaptive_response_action

B.

| rest /services/alerts/correlationsearches

C.

| rest /services/alerts/alert actions/_acl

D.

| rest /services/alerts/alert_actions

Buy Now
Questions 15

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

Options:

A.

user_id

B.

user

C.

action

D.

identity

Buy Now
Questions 16

Below is an example of a Sysmon process create log. Which EventCode would be associated with this log entry?

SPLK-5002 Question 16

Options:

A.

EventCode=1

B.

EventCode=4

C.

EventCode=3

D.

EventCode=2

Buy Now
Questions 17

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?

Options:

A.

Threat Intelligence

B.

Data models

C.

Analytic Stories

D.

Assets & Identities framework

Buy Now
Questions 18

Which of the following is a methodology to help prevent malicious lateral movement?

Options:

A.

Breakglass

B.

Lockheed Martin Cyber Kill Chain®

C.

MITRE ATT & CK®

D.

Zero Trust

Buy Now
Questions 19

An engineer has been asked to build a new dashboard after an increase in login failures across the organization ' s Microsoft Azure domain. They need to construct a search to only display failed logins for their Azure Active Directory users and create a visualization that will help quickly identify failed logins that originate outside of North America. Which search and visualization type combination will achieve this?

Options:

A.

Azure sign-in search/visualization combination using a Cluster Map but not the required failed-login condition

B.

Azure sign-in search using the alternative geographic visualization shown as a Choropleth Map

C.

Azure sign-in search using the alternative failure/geographic combination shown as a Choropleth Map

D.

Azure AD failed-login search using geographic coordinates with a Cluster Map

Buy Now
Questions 20

What can an engineer use to capture contextual values from a dashboard and create a drilldown to link to a new search?

Options:

A.

Aliases

B.

JSON

C.

Tokens

D.

Environment variables

Buy Now
Questions 21

Which type of correlation search reviews the events in the risk index and uses an aggregation of events impacting a single risk object to generate risk notables?

Options:

A.

Risk Category

B.

Risk Rule

C.

Risk Incident Rule

D.

Risk Incident Notable

Buy Now
Questions 22

When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform creates its column stores?

Options:

A.

Max summarization search time

B.

Backfill range

C.

Accelerate until maximum time

D.

Summary range

Buy Now
Questions 23

Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?

Options:

A.

Knowledge objects

B.

Commands

C.

Lookups

D.

Macros

Buy Now
Questions 24

Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?

Options:

A.

TA-ThreatIntel

B.

ESS-Intel

C.

SA-ThreatIntelligence

D.

SA-ESSIntel

Buy Now
Questions 25

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

Options:

A.

Perimeter firewalls should be measured on both the number of connections they permit and the number they block.

B.

Perimeter firewalls are exposed to the Internet and therefore subject to automated scanners and attack tools.

C.

The metric is too high level and should instead be broken down by the type of block.

D.

This is a Key Result Indicator, not a KPI; it measures the results of the perimeter firewall ' s actions rather than the performance of the firewall.

Buy Now
Questions 26

What does the following search do?

source=WinEventLog:security* sourcetype= " WinEventLog* " EventCode=4688

| stats count, values(process) as process by parent_process_name

Options:

A.

Displays a count of processes created by the same user.

B.

Displays a list of newly created processes and the user that created them.

C.

Displays a count of processes created by the same child process.

D.

Displays a list of processes and their parent processes.

Buy Now
Questions 27

What document can be helpful in understanding the prioritization of risk when comparing entities in an organization?

Options:

A.

A hierarchical organization chart

B.

Infrastructure architecture diagrams

C.

Application architecture diagrams

D.

Business Continuity or Disaster Recovery plan

Buy Now
Questions 28

The SOC manager has a desire to measure mean time to acknowledge finding (notable event) in order to meet a desired service-level objective. Which two fields can be used to measure the difference?

Options:

A.

Status, Owner

B.

Urgency, Status

C.

Severity, Owner

D.

User, Status

Buy Now
Questions 29

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

Options:

A.

service_intel

B.

http_intel

C.

certificate_intel

D.

ip_intel

Buy Now
Questions 30

Which of the following is not a type of metadata that can be returned by the metadata command?

Options:

A.

hosts

B.

sources

C.

assets

D.

sourcetypes

Buy Now
Questions 31

Based on this example image, if it is detected that a member has been added to a security-enabled local group, how many risk events will be created?

SPLK-5002 Question 31

Options:

A.

20

B.

1

C.

10

D.

2

Buy Now
Exam Code: SPLK-5002
Exam Name: Splunk Certified Cybersecurity Defense Engineer
Last Update: Oct 5, 2026
Questions: 105

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now SPLK-5002 testing engine

PDF (Q&A)

$31.5  $104.99
buy now SPLK-5002 pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 05 Oct 2026