Defenses, Data Sources, and SIEM Best Practices
SPLK-5001 · 60 questions
- A city SOC already has a perimeter firewall. Leadership asks who connected to the water-plant jump host. Which data source is most useful?
- After suspected malware on a clerk PC, which telemetry best answers which process spawned and which files were written?
- A municipal mailbox may have new forwarding and inbox rules after a suspected email compromise. Which sources should the analyst pull?
- Analysts want to hunt newly registered C2 domains used against city workstations. Where should they look first?
- A secure web gateway sits on staff egress. Leadership asks which clerk visited a phishing lure URL. Why do proxy or Web logs beat raw NetFlow alone?
- A county IDS fires on a library VLAN, and Enterprise Security also shows a notable. How should the analyst treat the two systems?
- A vendor laptop obtained an IP on the library VLAN. Which defense-system logs best explain how that device joined?
- A vulnerability scan shows the utilities portal as exploitable. The analyst still needs to know who logged in last night. What role do the scanner results play?
- The treasurer's SaaS mailbox shows impossible-travel sign-ins. Which source is most useful for that account-takeover analysis?
- Leadership asks who changed the S3 bucket policy on the municipal data lake. Which telemetry answers that control-plane question?
- A county SOC believes an attacker is hopping from a clerk workstation onto file shares with stolen domain credentials rather than new malware. Which data source is most useful for confirming lateral movement via valid accounts?
- A city firewall shows 10.20.30.40 contacting a rare destination at 02:00, and the SOC must name the laptop and the staff identity that held that address. What should the analyst combine?
- A transit edge firewall's syslog reports a blocked session but has already dropped the protocol fields the analyst needs. Which analysis tool should the analyst use next?
- The city SOC matches a quarantined file hash to an Enterprise Security threat list. Unless a blocking control is also in the path, what does that match provide?
- A clerk mailbox may have sent a large archive off-network, and the wastewater plant reported a PLC setpoint change in the same hour. Which source is useful for the data-leaving question and should not be first for the PLC change?
- Investigators need to know whether the night operator was physically inside the water plant when a suspicious workstation logon occurred. What can physical badge logs provide?
- A county just deployed a SOAR platform next to Enterprise Security. The first hunt for unusual treasurer-account logons still needs a primary data source. What should the analyst pick?
- A wastewater-process question is whether anyone used the jump host and then changed a pump setpoint through the industrial firewall. Which sources are useful?
- The city mail gateway quarantined an unknown attachment on a permitting clerk's message. Which analysis tool should the SOC use to learn what the file does?
- During one city incident, the IR lead asks who logged in as the treasurer, what that account resolved in DNS, and what binary ran on the workstation. How should the analyst pick the most useful data sources?
- County edge traffic is split across two firewall vendors that name source and destination fields differently. How should an Enterprise Security analyst write one investigation search that covers both?
- A clerk-login failure on the treasurer workstation needs a CIM data-model search. Which data model should the analyst use?
- The SOC needs a fast count of failed logons for the treasurer account across last week. Which SIEM search approach is the best practice in Enterprise Security?
- An analyst's tstats search on the Authentication data model returns no failed logons for the county DC, but raw WinEventLog:Security events exist. What should the analyst check before blaming the domain controller?
- Enterprise Security is installed, but the Access and Network domain dashboards stay empty even though firewall and Windows logs are indexed. What is missing?
- A wastewater historian should raise urgency when it appears on a notable. What does the Asset and Identity framework add so that happens?
- Enterprise Security still creates notables on a county file server, but owner, priority, and urgency look blank or wrong. What should the analyst diagnose?
- A civic workstation's DHCP hostname does not match its DNS name, and Asset and Identity never attaches owner or priority to the notable. Which keys does A&I use to join events to assets?
- A municipal mail-relay event is CIM-mapped with user, srcuser, and destuser populated. The question under investigation is which clerk identity sent the message through the relay. Which field should the analyst filter on?
- A city analyst searching NetworkTraffic filters src to the edge firewall hostname and no client sessions appear. What was confused?
- Help desk tells the SOC the city was breached because an IDS signature fired toward the elections file server. Which CIM field should the analyst check first before escalating?
- The county EDR may have seen a malware family on a clerk PC. Which CIM fields on the Malware data model answer that, rather than url?
- A parks-site watering-hole visit is the investigative question. Which CIM fields, on which data model, should the analyst use?
- A transit analyst sees rare egress from a station kiosk and needs to know whether it was HTTPS or a raw high-port beacon. Which CIM fields characterize that egress?
- Both the civic firewall and the EDR wrote overlapping events for the same clerk workstation. How should the analyst tell which product produced a given event?
- A city SOC wants one brute-force correlation to cover both the Palo Alto and Cisco ASA in front of the permitting portal. Analysts still paste vendor field names into every search. What is the SIEM best-practice next step?
- A county IR lead hunts a wastewater-plant login from two minutes ago. A tstats search on the accelerated Authentication data model is empty, but raw WinEventLog:Security shows the event. What should the analyst conclude?
- A city analyst is drafting an Enterprise Security correlation search for after-hours admin logons on court case-management servers. Which dataset should that search use?
- A terminated assessor clerk still shows as active staff on notables because the identity lookup last refreshed before HR finished offboarding. What SIEM problem is that?
- The elections file server is marked critical in the Asset lookup. A malware notable fires on that host. How should urgency be handled?
- A parks notable names a seasonal intern's user and a kiosk src. What is the CIM-correct way to see that intern's logons, then egress, then browsing?
- The city onboarded a new school-district web proxy. Raw events appear in Search, but the Enterprise Security Web Security Domain dashboard stays empty. What should the analyst diagnose?
- A county just started sending WinEventLog:Security from the sheriff records LAN. How should the analyst find which detections that sourcetype unlocks?
- The city wants AWS CloudTrail detections for the permitting buckets. Splunk Security Essentials and Enterprise Security content search show those detections require a CloudTrail sourcetype that is not onboarded. What should the analyst tell the team?
- A civic domain controller serving the courts OU is seeing a burst of failed logons. Which on-prem sourcetype should hold the brute-force evidence?
- The treasurer's Microsoft Entra ID account shows a sign-in from an unfamiliar country. Which cloud sourcetype should the analyst pull first?
- A small city's Splunk Security Essentials data-source checklist shows rich firewall syslog but no DNS. Command-and-control content is marked weak. What should the analyst conclude?
- The library consortium's Enterprise Security Web domain dashboard is empty, while the Access domain shows staff logons. What is the most likely data-source assessment?
- Transit edge devices now send pan:threat. How should analysts find official detections and dashboards for that sourcetype?
- The housing authority has an on-prem domain controller plus Entra ID for cloud apps. A privileged-logon hunt used only Entra content. What did the hunt miss?
- Wastewater historians send a custom OT sourcetype. Splunk Security Essentials shows no matching content. What is the right next step?
- Windows security was onboarded as the custom sourcetype citywinsec instead of WinEventLog:Security. Security Essentials content keyed on the standard name shows nothing. Why?
- The city council wants a statement that ransomware detections are live. What should the analyst do first?
- Someone created an IAM user and attached AdministratorAccess in the city's AWS account. Which sourcetype holds that API evidence?
- A clerk's mailbox grew a hidden forwarding rule. Separately, the SOC needs the path of one phishing message through Exchange Online. Which sourcetype split is correct?
- A library just onboarded Sysmon. Where should the analyst look first for process-creation and DNS-query detections already written for that sourcetype?
- While looking for content tied to a new court-camera NVR sourcetype, a junior analyst only searches for a saved search whose name matches the sourcetype. What else should they include?
- Splunk Security Essentials shows the city has Cisco ASA events, but CIM NetworkTraffic fields are empty. What pair of actions is the best-practice path?
- Public health's cloud EHR is SaaS and has no Splunk-supported ehr:cim sourcetype. How should the analyst assess useful data?
- The housing authority wants a documented check that account-takeover content is actually usable. What is the correct sequence?