SPLK-5002 Exam Question 11
What is the primary purpose of correlation searches in Splunk?
SPLK-5002 Exam Question 12
For detections that leverage a CIM data model, which aspect of the configuration is responsible for determining which indexes are being searched?
SPLK-5002 Exam Question 13
The SOC notices over the course of an investigation there are numerous logs like the following:
14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query:
reallybad.c2.com IN A response: SERVFAIL +E
What detection should be created to alert on this behavior for the future?
14-Apr-2024 20:16:49.083 client 15.111.116.918*18345 UDP: query:
reallybad.c2.com IN A response: SERVFAIL +E
What detection should be created to alert on this behavior for the future?
SPLK-5002 Exam Question 14
Which Splunk Enterprise Security add-on facilitates the ingestion of Threat Intelligence data?
SPLK-5002 Exam Question 15
A threat actor group has begun a campaign that is relevant to an organization. How can the organization's engineer raise the risk score for corresponding intelligence matches in the applicable threat collection?
