Splunk Certified Cybersecurity Defense Analyst - SPLK-5001 Exam Practice Test

Question 1
This technique is used by attackers to hide the presence of components like programs, files, and network connections by hooking into the OS and intercepting system API calls. It can reside at the user or kernel level. What technique is this?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
Storing log checksums in a public blockchain system is most closely linked to which security concept?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
Which Splunk app can help an organization inventory their data then find, deploy, and evaluate security detections to advance their security journey?

Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
Which part of the CIA triad is the opposite of destruction of information?

Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
An analyst notices that one of their servers is sending an unusually large amount of traffic, gigabytes more than normal, to a single system on the Internet. There doesn't seem to be any associated increase in incoming traffic.
What type of threat actor activity might this represent?

Correct Answer: A
Question 6
Which dashboard in Enterprise Security would an analyst use to generate a report on users who are currently on a watchlist?

Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
An analyst learns that several types of data are being ingested into Splunk and Enterprise Security, and wants to use the metadata SPL command to list them in a search. Which of the following arguments should she use?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 8
The eval SPL expression supports many types of functions. Which of these function categories is not valid with eval?

Correct Answer: D
Question 9
Which of the following is a reason to use Data Model Acceleration in Splunk?

Correct Answer: B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).