Cyber Landscape Frameworks and Standards
SPLK-5001 · 30 questions
- A county SOC manager is filling a night-shift opening. The job poster lists triaging notables on Incident Review, assigning dispositions, and opening investigations. Which SOC role owns that work?
- City water utilities keeps getting noisy correlation searches after a new historian was onboarded. Someone must tune the search, fix CIM mappings, and adjust risk scores. Which role should leadership assign?
- The mayor's office wants a three-year plan for how the municipal SOC will cover MITRE ATT&CK, which data sources to buy, and how Enterprise Security plus SOAR will mature. Which role owns that plan?
- A transit-authority SOC chart shows L1 queue work, L2 deep-dive investigation, L3 hunt and IR surge, plus a separate engineer pod and a CISO-aligned architect. What organization does that chart describe?
- After a library ransomware scare, leadership asks who should write a new "suspicious SMB spike" correlation search and who should work the first notable it creates. How should those duties be split?
- A public-health clinic SOC has one person working the notable queue and also building SOAR playbooks. How should the playbook-build work be classified?
- The county architect publishes a detection-coverage heatmap against ATT&CK and a data-onboarding roadmap. A night-shift analyst treats that as a prompt to redesign CIM mappings before clearing the queue. What is the correct hand-off among the three SOC roles?
- A 911/PSAP SOC runbook says the on-duty analyst may run an ad-hoc Adaptive Response ping from a notable but may not edit that correlation search's scheduled trigger. What does that rule correctly bound?
- Fire/EMS leadership wants someone who can explain to the board why the department bought Enterprise Security and how the program maps to NIST CSF functions. Which role owns that briefing?
- A school-district SOC lists essanalyst versus essadmin style permissions. Which pairing of work to ES capability is correct?
- A city CISO asks how Enterprise Security uses MITRE ATT&CK rather than just hanging a poster on the SOC wall. What is the primary mechanism?
- County detections are tagged to Kill Chain stages so an analyst can see a notable is C2 rather than delivery. How should that tagging be understood?
- A wastewater plant tabletop uses the Diamond Model of adversary, capability, infrastructure, and victim. How should the analyst apply those vertices in Enterprise Security?
- The library director wants the SOC to just block the hashes from a malware sample. Using the Pyramid of Pain, what should the analyst explain about durable detections?
- A municipal compliance officer asks whether Enterprise Security is NIST. What should the analyst say?
- The county wants CIS Critical Security Controls coverage. How do Splunk Security Essentials and Enterprise Security content browsers help the team?
- A transit SOC heatmap in Enterprise Security shows ATT&CK technique coverage from enabled correlation searches. What actually produces that coverage view?
- Public-works leadership calls MFA a framework and MITRE ATT&CK a control. How should the analyst correct that mix-up and place Splunk?
- A court-system SOC enables annotations so a risk notable lists several ATT&CK techniques contributed by different risk events. What is the purpose of those annotations on the risk story?
- The city's cyber-insurance questionnaire asks which standard the SOC follows. How should the analyst treat Splunk in that answer?
- A school district wants zero trust because the term appears in industry blueprints, and a board member asks which Enterprise Security dashboard to open for it. What is the accurate framing?
- Elections staff ask how Splunk incorporates MITRE ATT&CK in day-to-day SOC work rather than in a one-time slide. What is the operational answer?
- A records clerk's laptop is encrypted by ransomware. The county clerk cares that sealed case files can no longer be read. Which information-assurance impact is the clerk describing?
- Someone tampers with wastewater chemical-dose setpoints in the historian, but the pumps still run. Which information-assurance property is hit first?
- A DDoS against the city's permitting portal means residents cannot pull building permits. Which CIA property is primarily affected?
- The library board wants a one-line risk definition the civic SOC can reuse when reviewing malware notables. Which definition should the analyst give?
- The county risk register lists a 911 CAD outage as high impact even though its likelihood is low. How should the analyst use that when prioritizing Enterprise Security detections?
- After identifying phishing risk to municipal email, which set names the basic risk responses the city can choose?
- Asset and Identity marks the elections voter-file server as high priority and a lab PC as low. How should Risk-Based Alerting treat those assets?
- A public-health clinic must protect ePHI confidentiality and keep the after-hours nurse line available. What should the analyst tell leadership about this CIA trade-off?