SPLK-5001 Exam Question 1
A Risk Notable Event has been triggered in Splunk Enterprise Security, an analyst investigates the alert, and determines it is a false positive. What metric would be used to define the time between alert creation and close of the event?
SPLK-5001 Exam Question 2
What is the first phase of the Continuous Monitoring cycle?
SPLK-5001 Exam Question 3
Which of the following data sources can be used to discover unusual communication within an organization's network?
SPLK-5001 Exam Question 4
When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?
SPLK-5001 Exam Question 5
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain to be mapped to Correlation Search results?
