Based on the provided screenshot, it's discovered that different machines or accounts have been associated with the shown threat objects. Enterprise Security has identified that these machines and accounts all point back to one owner - Fyodor. Which two frameworks in ES are responsible for programmatically associating this information together?
Correct Answer: C
The Risk framework aggregates risky behaviors and assigns risk scores to users, systems, or accounts, while the Assets & Identities framework enriches events by correlating them with identity and asset information. Together, they programmatically associate different machines and accounts back to a single owner, as shown with Fyodor in the screenshot.
Question 12
Risk scores are associated with how many levels of risk in Enterprise Security by default?
Correct Answer: C
By default, Splunk Enterprise Security associates risk scores with five levels: Info, Low, Medium, High, and Critical. These levels help prioritize security events and focus analyst attention on the most impactful risks.
Question 13
When generating documentation for a security program, what key element should be included?
Correct Answer: C
Key Elements of Security Program Documentation A security program's documentation ensures consistency, compliance, and efficiency in cybersecurity operations. #Why Include Standard Operating Procedures (SOPs)? Defines step-by-step processesfor security tasks. Ensures security teams followstandardized workflowsfor handling incidents, vulnerabilities, and monitoring. Supportscompliance with regulationslikeNIST, ISO 27001, and CIS controls. Example: SOP forincident responseoutlines how analysts escalate security threats. #Incorrect Answers: A: Vendor contract details# Vendor agreements are important butnot core to a security program's documentation. B: Organizational hierarchy chart# Useful for internal structure butnot essential for security documentation. D: Financial cost breakdown# Related to budgeting, not security operations. #Additional Resources: NIST Security Documentation Framework Splunk Security Operations Guide
Question 14
What is the primary function of summary indexing in Splunk reporting?
Correct Answer: B
Primary Function of Summary Indexing in Splunk Reporting Summary indexing allows pre-aggregation of data to improve performance and speed up reports. #Why Use Summary Indexing? Reduces processing time by storing computed results instead of raw data. Helps SOC teams generate reports faster and optimize search performance. Example: Instead of searching millions of firewall logs in real-time, a summary index stores daily aggregated counts of blocked IPs. #Incorrect Answers: A: Storing unprocessed log data # Raw logs are stored in primary indexes, not summary indexes. C: Normalizing raw data for analysis # Normalization is handled by CIM and data models. D: Enhancing the accuracy of alerts # Summary indexing improves reporting performance, not alert accuracy. #Additional Resources: Splunk Summary Indexing Guide Optimizing SIEM Reports in Splunk
Question 15
When building detections using the Authentication Data Model, which values are recommended for use against the action field?
Correct Answer: B
Within the CIM Authentication Data Model , the action field represents the outcome or state of an authentication operation. The recommended normalized values represented by the question are success, failure, pending, and error . Normalization is critical because authentication technologies use highly variable native terminology. A Windows event may represent an authentication result through one event code, a VPN appliance through another vendor-specific status, and a cloud identity provider through a JSON result field. CIM maps those source-specific outcomes into common semantic values. A detection engineer can therefore write logic such as: action= " failure " without separately accounting for every vendor ' s native representation. allowed and blocked are more naturally associated with access or network-control decisions and do not describe the normalized authentication outcome being tested. Likewise, denied does not replace the CIM- normalized failure value in the answer set. Consistent use of the expected action vocabulary directly affects detection reliability. Incorrect mappings can cause failed authentications to disappear from CIM-based searches, dashboards, accelerated data-model queries, and threshold detections. Study Guide topics: Authentication Data Model; CIM; action; normalized authentication outcomes; data mapping; cross-source detection engineering.