Free SPLK-5001 Exam Braindumps (page: 5)

Page 4 of 18

Upon investigating a report of a web server becoming unavailable, the security analyst finds that the web server's access log has the same log entry millions of times:

147.186.119.200 - - [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733

What kind of attack is occurring?

  1. Denial of Service Attack
  2. Distributed Denial of Service Attack
  3. Cross-Site Scripting Attack
  4. Database Injection Attack

Answer(s): B



According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?

  1. Domain names
  2. TTPs
  3. NetworM-lost artifacts
  4. Hash values

Answer(s): D



An analysis of an organization's security posture determined that a particular asset is at risk and a new process or solution should be implemented to protect it. Typically, who would be in charge of implementing the new process or solution that was selected?

  1. Security Architect
  2. SOC Manager
  3. Security Engineer
  4. Security Analyst

Answer(s): C



Which of the following is a correct Splunk search that will return results in the most performant way?

  1. index=foo host=i-478619733 | stats range(_time) as duration by src_ip | bin duration span=5min | stats count by duration, host
  2. | stats range(_time) as duration by src_ip | index=foo host=i-478619733 | bin duration span=5min | stats count by duration, host
  3. index=foo host=i-478619733 | transaction src_ip |stats count by host
  4. index=foo | transaction src_ip |stats count by host | search host=i-478619733

Answer(s): A






Post your Comments and Discuss Splunk® SPLK-5001 exam with other Community members:

SPLK-5001 Exam Discussions & Posts