Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 6Objective 8

6.8 Describe Managing, Orchestrating, and Automating Security Information and Events with Splunk 350-701 Practice Questions (Page 2)

Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
8concepts
15%of the exam

Questions 6–10

  1. 6application · medium

    A SOC analyst is investigating a series of failed login attempts followed by a successful login from the same source IP address within a 10-minute window. The analyst needs to determine if this pattern indicates a successful brute-force attack. The authentication logs are indexed in Splunk with a sourcetype of 'linux:auth'. Which SPL query will identify the successful login that followed multiple failures from the same source IP?

    Select an answer first
  2. 7foundation · easy

    In Splunk, which component is used to define a condition that triggers an alert when a search returns specific results?

    Select an answer first
  3. 8foundation · easy

    Which Splunk capability is most directly used to support compliance reporting, such as demonstrating that firewall logs are retained for a required period?

    Select an answer first
  4. 9application · medium

    A SOC is required to produce a monthly compliance report showing all authentication events for user accounts with administrative privileges. The report must include the username, source IP, timestamp, and success/failure status. The authentication logs are in Splunk with a sourcetype of 'windows:security'. Which SPL query will generate the required report data?

    Select an answer first
  5. 10foundation · easy

    What is the purpose of a correlation search in Splunk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.