Splunk
SPLK-5002
Q1:
Which elements are critical for documenting security processes? (Choose two)
☐
A
Detailed event logs☐
B
Visual workflow diagrams☐
C
Incident response playbooks☐
D
Customer satisfaction surveys
Splunk
SPLK-5002
Q2:
Which practices strengthen the development of Standard Operating Procedures (SOPs)? (Choose three)
☐
A
Regular updates based on feedback☐
B
Focusing solely on high-risk scenarios☐
C
Collaborating with cross-functional teams☐
D
Including detailed step-by-step instructions☐
E
Excluding historical incident data
Splunk
SPLK-5002
Q3:
What Splunk process ensures that duplicate data is not indexed?
○
A
Data deduplication○
B
Metadata tagging○
C
Indexer clustering○
D
Event parsing
Splunk
SPLK-5002
Q4:
What is the primary function of a Lean Six Sigma methodology in a security program?
○
A
Automating detection workflows○
B
Optimizing processes for efficiency and effectiveness○
C
Monitoring the performance of detection searches○
D
Enhancing user activity logs
Splunk
SPLK-5002
Q5:
What are the benefits of incorporating asset and identity information into correlation searches? (Choose two)
☐
A
Enhancing the context of detections☐
B
Reducing the volume of raw data indexed☐
C
Prioritizing incidents based on asset value☐
D
Accelerating data ingestion rates