When setting Common Information Model (CIM) accelerations, which parameter should be defined to set how far back in time (specified as a relative time string) the Splunk platform creates its column stores?
When creating detections, which of the following sequences would result in the most performant SPL query?
When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?
For detections that leverage a CIM data model, which aspect of the configuration is responsible for determining which indexes are being searched?
While working with the SOC analysts to review current contextualization processes, a request for automation has been raised by the SOC team. They are asking for a new automation that will check a potentially malicious URL against a remote URL filtering list. Which of the following options will work for them?
Which Splunk feature makes SPL searches shorter and reusable by inserting it into search strings?
Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?
What should a security engineer prioritize when building a new security process?
An engineer has been asked to build a new dashboard after an increase in login failures across the organization ' s Microsoft Azure domain. They need to construct a search to only display failed logins for their Azure Active Directory users and create a visualization that will help quickly identify failed logins that originate outside of North America. Which search and visualization type combination will achieve this?
Based on the provided screenshot, different machines or accounts have been associated with chosen threat objects. Which two Enterprise Security frameworks are responsible for programmatically associating this information?
When creating a case in Splunk SOAR, which action should be taken to correlate various findings (risk notables) to ensure all are actioned?
A cyber defense engineer plays a role in maintaining a secure SOAR Cloud configuration. Which network security statement is correct about SOAR Cloud?
An automation engineer for the Wonderland SOC has configured a new asset and is getting an HTTP 403 response code. Which of the following is a possible cause of the error code?
How can you incorporate additional context into notable events generated by correlation searches?
What does the following search do?
source=WinEventLog:security* sourcetype= " WinEventLog* " EventCode=4688
| stats count, values(process) as process by parent_process_name
An effective method for building automation workflows is to follow the OODA (Observe, Orient, Decide, Act) loop stages. When transitioning between the Decide and Act stages, what additional step should be included before automating the Act stage?
Which of the following is not a type of metadata that can be returned by the metadata command?
The SOC Manager requested a better method to standardize the list of tasks that analysts follow when they evaluate events or cases. Which Splunk SOAR feature allows the creation of SOPs based on criteria like the type of event or attack vector?
If a correlation search cannot be run at the configured time, which scheduling option should an engineer use to ensure there are no backfill gaps in data?
One of the goals of a detection engineer is to facilitate the triage process by providing the analyst as much context as possible. One way of accomplishing this is to provide context options through the use of which of the following settings?
Which fields are used to determine asset priority, when priority is assigned through an asset and identity lookup?
Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they ' ve been utilizing for testing a detection named TestSearchDevelopment?
Below is an example of a Sysmon process create log. Which EventCode would be associated with this log entry?

Which of the following actions will allow access to a list of alert actions via the API?
Consider the following series of events:
4:00 GMT Detection runs for interval 3:30–4:00
4:30 GMT Detection runs for interval 4:00–4:30
4:35 GMT Event 1 occurs on an endpoint
4:45 GMT Event 1 is indexed
5:00 GMT Detection runs for interval 4:30–5:00
5:05 GMT Event 1 finding is added to ES with timestamp 4:35
5:24 GMT Event 2 occurs on an endpoint
5:30 GMT Detection runs for interval 5:00–5:30
5:35 GMT Event 2 is indexed
6:00 GMT Detection runs for interval 5:30–6:00
What is the problem with the detection schedule chosen and how can it be solved?
Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?
An engineer wants to track and report on all authentication to corporate assets and wants to prioritize critical assets without significantly increasing the number of findings created. What process could be used to accomplish this goal?