Investigation, Event Handling, Correlation, and Risk
SPLK-5001 · 60 questions
- A city SOC manager treats continuous monitoring as the quarterly audit spreadsheet of civic systems reviewed last quarter. What should the defense analyst explain instead?
- A clerk workstation is ticketed as slow, and a matching notable is already in the Analyst Queue. The night analyst starts by wiping the PC. What should have been the first of Splunk's five investigation stages?
- After identifying a notable on a county permitting host, the analyst's next move is to reimage every PC in the department. Which Splunk investigation stage should come next instead?
- A county SOC has scoped a treasurer-account notable to one user and a four-hour window. Leadership wants the account disabled before anyone looks at contributing events. What belongs in Splunk's third investigation stage first?
- Analysis confirmed a treasurer identity used a public kiosk to reach a listed command-and-control host. When should the analyst disable the account, block that host, or isolate the kiosk?
- A library catalog incident is contained. The city wants to close the case and skip everything after remediation. Which work belongs in Splunk's fifth investigation stage?
- A night-shift analyst sees a 911 CAD notable and immediately pulls the CAD network interface to contain it, skipping analysis. What is wrong with that sequence?
- A city manager lists Splunk's five investigation stages and puts continuous monitoring as stage one. How should the analyst correct that mix-up?
- An analyst moves a parks notable from New to In Progress to Resolved and tells the shift lead those statuses are Splunk's five investigation stages. What should the lead clarify?
- After a permitting-portal incident, the city restored service, documented the case, and closed the notable. What should the SOC still confirm about continuous monitoring?
- County leadership asks for dwell time on last week's finance incident. An analyst reports the 40 minutes the notable was assigned. What is dwell time?
- A city CIO funds more unused Enterprise Security dashboards and claims mean time to detect will drop. What does MTTD actually measure?
- The municipal SOC defines MTTR as starting at detection and ending when the threat is contained. A parks kiosk sat undetected for six days and was then isolated in 45 minutes. Which statement about MTTR is correct?
- Leadership wants lower dwell on the county network and proposes buying more wall screens for the SOC. What actually moves dwell?
- A city SOC brags about a 20-minute MTTR while attackers remain on the water SCADA jump host for two weeks before anyone notices. What trap should the metrics review expose?
- A transit SOC scoreboard ranks analysts by tickets closed per hour, and dispositions are being rubber-stamped. What should analysts help the city define instead?
- The county wants time-in-status numbers that feed MTTR. An IT manager orders a new ITSM tool because Splunk cannot time a notable. Where should the municipal SOC measure that?
- Leadership wants one county-wide MTTR target for both 911 CAD and a library kiosk. How should the analyst set expectations?
- An EDR notable fires on a city software-packaging tool that IT already approved for clerk image builds. The analytic matched real packaging behavior. Which disposition should the analyst assign?
- A correlation search treats every municipal syslog line as a failed logon because a technical add-on maps the wrong field. Which disposition fits?
- Yesterday's infected DHCP address now belongs to the mayor's laptop, and a malware notable names that laptop. The lease was reused after the infected host left. Which disposition is correct?
- Investigation confirms credential stuffing against the utilities payment portal that the city did not authorize. Which disposition should the analyst assign?
- Night shift has not finished scoping a wastewater-plant notable. A supervisor wants it labeled True Positive so the queue looks clear at dawn. What should the analyst do?
- An elections-office notable is confirmed malicious, but containment is still underway. A clerk sets status to Resolved, thinking that means False Positive. What should the analyst keep separate?
- A civic analyst correctly assigns False Positive - Incorrect Analytic Logic to a noisy parks notable and then ends the shift. What is still required?
- A county SOC sees two port-scan notables after the same night: one source is the city's authorized vulnerability scanner during the published window, and the other is an unknown external host. How should the analyst disposition them?
- A wastewater SOC analyst is told to use SPL against civic indexes and the Authentication data model while scoping a notable. What is SPL in that workflow?
- A 911 PSAP analyst has a red syslog line in Search and a tracked item on Analyst Queue after a correlation search ran. Which object is the Notable Event they triage?
- The county treasurer account collected several cheap risk events—rare VPN, a new mailbox rule, off-hours admin—without paging the on-call. A queue item appears only after the aggregated score crosses the city's threshold. What fired?
- A risk notable for suspicious activity around the county treasurer shows a rising score. Which entity is the Risk Object that holds that score?
- A risk notable fired on the treasurer identity. The analyst needs to explain why the score exists before briefing finance. What should they expand?
- A library SOC analyst needs to run ping or send a notable to SOAR from a correlation search or from an open notable. Which ES construct is that action framework?
- A transit analyst says notables and Adaptive Response are mutually exclusive, so a correlation search that creates a notable is not using AR. What is the correct relationship?
- The municipal VPN detection for a logon from a rare city is too cheap to page the on-call by itself. How should that hit become part of a later risk notable?
- A clerk-account risk notable is in the city queue. What is the intended sequence using the notable, contributing events, and SPL together?
- A fire/EMS analyst finds a concerning firewall deny in Search that no correlation search has tracked. Is that event a notable?
- An elections risk story shows scores on both the elections clerk (user) and the elections workstation (system). How should the analyst treat those risk objects?
- From a courts notable, the analyst runs ad-hoc ping and nslookup. What job do those Adaptive Response actions do compared with a risk notable?
- The city SOC needs the built-in queue of notables and findings with title, urgency, owner, status, disposition, and time. Which dashboard is that?
- County leadership asks the analyst to close civic tickets from the Risk Analysis dashboard. What is that dashboard actually for?
- The CIO wants a civic-wide snapshot of notables by domain and urgency for the morning briefing, not a packet decode. Which built-in ES view fits?
- A municipal-accounts investigation needs authentication patterns, rare logons, and access anomalies. Which ES dashboard family should the analyst open first?
- The city needs malware and process context on clerk workstations, then firewall and IDS context on the same incident. Which Security Domain dashboards match those telemetry types?
- Clerks are hitting a fake benefits-enrollment site. The analyst needs URLs, categories, and proxy users. Which ES dashboard family is the right place?
- The SOC must assemble one permitting clerk's activity across sources instead of bouncing between five raw searches. Which ES capability is built for that?
- A housing-authority account shows logons at improbable hours from an unusual geography and a sudden volume spike. The lead says it might be a DDoS dashboard problem. Which ES view is actually built for that access pattern?
- The county wants protocol-level DNS and HTTP context on civic hosts. When will Protocol Intelligence / stream dashboards actually show that data?
- Leadership asks two questions: which civic hosts talked to a listed C2, and how analysts handled the resulting notables. Which dashboard pairing answers those?
- The city SOC still pages the on-call for every cheap signal—rare VPN, new mailbox rule, off-hours admin on the treasurer account. What RBA change should they make?
- A civic engineer asks the analyst what an Enterprise Security correlation search actually is before they request a new detection. Which definition should the analyst use?
- A county SOC is adding a correlation search for a weak civic signal: a treasurer VPN from a rare city. Leadership wants fewer single-signal pages to on-call. How should that search's adaptive responses be designed?
- A city finance clerk and a wastewater historian both need scores from new RBA content. How should the risk objects be typed?
- A municipal SOC is creating several weak risk rules for parks, courts, and permitting accounts. What should each rule include so a later risk notable automatically tells an ATT&CK story?
- The city set the risk-notable threshold so low that Incident Review looks like the old one-alert-per-signal queue. What RBA adjustment should the SOC make first?
- A correlation search for wastewater firewall denies is flooding notables because one noisy historian produces hundreds of matching rows. What should be configured on the search so adaptive responses do not fire on every row?
- Nightly authorized vulnerability scans of the library catalog keep creating the same notables. The search logic is correct. What should the analyst use so those known-benign items leave the working queue without deleting history?
- A county analyst finds an elections clerk mailbox-forwarding pattern that no correlation search turned into a notable. What Enterprise Security action should the analyst take so the event is tracked in the queue?
- Leadership wants the county elections file server to start with a higher baseline risk than a library kiosk. How should that adjustment be made?
- The CIO asks why a utilities clerk now has a risk notable. What must the civic RBA stack provide so the analyst can explain the notable without guessing?
- A city analyst must request a new correlation search for permitting-portal account-takeover signals. What understanding is enough for that request without becoming the Enterprise Security administrator?