
CiscoCertified Network Professional Security
Domain 6Objective 8
6.8 Describe Managing, Orchestrating, and Automating Security Information and Events with Splunk 350-701 Practice Questions (Page 4)
Part of the Network Access, Visibility, and Enforcement domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
8concepts
15%of the exam
Questions 16–20
- 16
In Splunk, what is the primary purpose of assigning roles to users?
Select an answer first - 17
A SOC uses Splunk to detect phishing emails reported by users. When a phishing email is detected, the team wants to automatically block the sender's email address in the email security gateway and notify the incident response team. The email security gateway has a REST API for blocking senders. Which Splunk feature should be used to automate this response?
Select an answer first - 18
A SOC manager wants to create a dashboard that shows the trend of security incidents over the past 30 days, broken down by incident type (e.g., malware, phishing, brute force). The dashboard should allow the manager to see the overall trend and the contribution of each incident type. Which Splunk visualization is best suited for this requirement?
Select an answer first - 19
A SOC manager wants to create a dashboard that shows the number of security events by severity level (critical, high, medium, low) for the last 24 hours, updated in near real-time. The dashboard will be displayed on a large monitor in the SOC for continuous monitoring. Which Splunk dashboard panel configuration best meets this requirement?
Select an answer first - 20
A security team wants to be notified immediately when more than 10 failed login attempts occur from a single source IP address within a 5-minute window. The team also wants to automatically create a ticket in their ITSM system when this condition is met. Which Splunk configuration should be used to meet both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.