SPLK-5001 Exam Question 1

A Risk Notable Event has been triggered in Splunk Enterprise Security, an analyst investigates the alert, and determines it is a false positive. What metric would be used to define the time between alert creation and close of the event?
  • SPLK-5001 Exam Question 2

    What is the first phase of the Continuous Monitoring cycle?
  • SPLK-5001 Exam Question 3

    Which of the following data sources can be used to discover unusual communication within an organization's network?
  • SPLK-5001 Exam Question 4

    When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?
  • SPLK-5001 Exam Question 5

    Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain to be mapped to Correlation Search results?