In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?
Correct Answer: B
In Risk-Based Alerting (RBA), a risk factor is a multiplier of risk applied based on the characteristics of a user or asset, such as criticality or sensitivity. This allows higher-risk entities to accumulate risk more quickly and ensures prioritization aligns with business impact.
Question 82
How can an engineer verify if results will return for a potential detection based on historical events within the organization?
Correct Answer: C
To verify if a potential detection will return results, the engineer should run the detection against production data in the same Splunk instance. This ensures the query is tested against actual historical events from the organization's environment, confirming whether it generates meaningful results.
Question 83
What methods improve risk and detection prioritization?(Choosethree)
Correct Answer: A,C,D
Risk and detection prioritization in Splunk Enterprise Security (ES) helps SOC analysts focus on the most critical threats. By assigning risk scores, integrating business context, and automating detection tuning, organizations can prioritize security incidents efficiently. Methods to Improve Risk and Detection Prioritization: Assigning Risk Scores to Assets and Events (A) Uses Risk-Based Alerting (RBA) to prioritize high-risk activities based on behavior and history. Helps SOC teams focus on true threats instead of isolated events. Incorporating Business Context into Decisions (C) Adds context from asset criticality, user roles, and business impact. Ensures alerts are ranked based on their potential business impact. Automating Detection Tuning (D) Uses machine learning and adaptive response actions to reduce false positives. Dynamically adjusts alert thresholds based on evolving threat patterns.
Question 84
Based on a recent red team exercise, an organization is highly concerned about pass the hash attacks especially including tools like Empire. Which Eventcode associated to PowerShell Script Block Logging would be used to detect this activity?
Correct Answer: D
EventCode=4104 is associated with PowerShell Script Block Logging, which records the full content of executed PowerShell scripts. This is critical for detecting malicious frameworks like Empire that rely on PowerShell for pass-the-hash and other attack techniques.
Question 85
When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?
Correct Answer: A
A total count of blocked firewall connections describes an outcome generated by the control , rather than measuring how effectively the firewall itself performs against an established operational objective. It is therefore better characterized as a Key Result Indicator (KRI) in the terminology used by the course material. For example, observing five million blocked connections does not demonstrate that a firewall is performing better than one that blocks one million. The total is heavily influenced by external conditions such as Internet scanning, bot activity, exposure of public services, and changing adversary traffic. The number can increase even when no improvement has occurred in firewall configuration, reliability, policy quality, or security effectiveness. A meaningful KPI should connect directly to measurable performance-for example control availability, policy deployment accuracy, remediation time, rule-review compliance, or another defined operational objective. Firewall-block volume may remain useful as contextual or trend information, but treating it as a performance metric can produce misleading conclusions about security-program effectiveness. The supplied study material contains this firewall KPI/KRI distinction. Study Guide topics: security metrics, KPI versus KRI, control effectiveness, perimeter security, security- program reporting.