Courseiva

CCNA Investigation And Risk Management Questions

38 questions · Investigation And Risk Management · All types, answers revealed

1
Multi-Selecteasy

Which TWO of the following are key components of a successful incident investigation workflow in Splunk ES?

Select 2 answers
A.Automated index deletion
B.Case documentation and updates
C.User password resets
D.Manual correlation search coding
E.Notable event triage
AnswersB, E

Documenting findings is critical for auditability and collaboration.

Why this answer

Triage and documentation are essential parts of the Incident Review and Case Management process.

2
MCQhard

When configuring an 'Adaptive Response' action, what does the 'Notable' action type do?

A.Updates the asset identity table.
B.Creates an entry in the Incident Review dashboard.
C.Assigns a risk score to an event.
D.Sends an email alert.
AnswerB

This is the primary function of the 'Notable' adaptive response action.

Why this answer

The 'Notable' action type specifically triggers the creation of a notable event in the Incident Review dashboard.

3
Multi-Selecteasy

Which THREE pieces of information are commonly found in a Splunk ES Case?

Select 3 answers
A.Investigation metadata (status, owner)
B.Analyst comments and notes
C.Raw indexer performance logs
D.Notable events associated with the case
E.System health metrics
AnswersA, B, D

Metadata keeps track of case state and assignment.

Why this answer

Cases are containers that hold key artifacts, comments from analysts, and links to relevant notable events.

4
Multi-Selecthard

Which TWO factors influence an object's final risk score in Splunk ES?

Select 2 answers
A.The number of users in the organization
B.The total disk space of the index
C.Individual risk event scores
D.The aggregation method (sum, average, max)
E.The operating system of the host
AnswersC, D

These are the base values that get added together.

Why this answer

The final score is influenced by the individual event scores and the aggregation method applied.

5
MCQmedium

An analyst needs to manually add an event to an existing case in Splunk ES. What is the correct procedure?

A.Edit the correlation search definition.
B.Modify the risk index directly.
C.Use the Case Management dashboard to search for the event ID.
D.Select the event in Incident Review and choose 'Add to Case'.
AnswerD

The 'Add to Case' action is directly available in the Incident Review interface.

Why this answer

From the Incident Review dashboard, analysts can select a notable event and use the 'Action' menu to assign it to an existing case.

6
Multi-Selectmedium

Which THREE dashboard categories in Splunk ES are most useful for risk-based investigation?

Select 3 answers
A.Risk Analysis
B.Security Posture
C.Incident Review
D.License Usage
E.User Activity Monitoring
AnswersA, B, C

This provides granular risk scoring data.

Why this answer

Risk Analysis, Incident Review, and Security Posture are the primary dashboards for investigation.

7
Multi-Selecteasy

Which THREE actions are part of the 'Incident Review' investigation workflow?

Select 3 answers
A.Updating system configuration files
B.Rebooting indexer nodes
C.Changing the status of a notable
D.Triage of new notable events
E.Assigning notables to an analyst
AnswersC, D, E

Updating status shows progress in the lifecycle.

Why this answer

Investigating involves triaging, assigning, and changing statuses.

8
MCQmedium

When reviewing an incident, how can an analyst verify if the notable event was generated by a specific correlation search?

A.By running a search for the object.
B.By checking the 'Search Name' field.
C.By checking the 'Event ID'.
D.By looking at the index name.
AnswerB

This field maps the notable event to the originating correlation search.

Why this answer

The 'Search Name' field in the Incident Review dashboard clearly identifies the correlation search that triggered the notable.

9
MCQeasy

What is the purpose of the 'Investigation Workbench' in Splunk ES?

A.To run administrative index maintenance.
B.To manage user identities.
C.To provide a unified view of incident artifacts.
D.To configure correlation searches.
AnswerC

It helps consolidate investigation data for analysts.

Why this answer

The Investigation Workbench provides a centralized view of all entities, events, and context related to a specific incident.

10
MCQeasy

When investigating a risk notable, which dashboard in Splunk ES provides a visual representation of the risk contributors for a specific user?

A.Threat Activity Dashboard
B.Access Anomalies Dashboard
C.Incident Review
D.Risk Analysis Dashboard
AnswerD

This dashboard displays the breakdown of risk scores by object and contributing events.

Why this answer

The Risk Analysis dashboard allows analysts to drill down into the specific risk events contributing to a user's total risk score.

11
MCQeasy

In the Incident Review dashboard, what does 'Status' represent?

A.The assignment to an analyst.
B.The severity of the threat.
C.The risk score of the notable.
D.The stage of the investigation workflow.
AnswerD

Status indicates where the incident is in the response process.

Why this answer

Status tracks the progress of an investigation, such as 'New', 'In Progress', or 'Closed'.

12
MCQmedium

A customer wants to exclude certain low-fidelity risk events from their Risk Notable correlation search. Where is the best place to define these exclusions?

A.Risk Index Retention Policy
B.Data Model Acceleration
C.Asset and Identity Table
D.Correlation Search Suppression
AnswerD

Notable Event Suppression allows analysts to define criteria to ignore specific events that should not trigger a notable.

Why this answer

Notable event suppression is the native method in Splunk ES to prevent specific event types from triggering notables based on criteria.

13
Multi-Selectmedium

Which TWO metrics are tracked in the 'Incident Review' dashboard's 'Notable Event' list?

Select 2 answers
A.Severity
B.Raw file path
C.Cluster replication factor
D.Status
E.License expiration date
AnswersA, D

Severity is a core column used for prioritization.

Why this answer

The dashboard displays core event information, including status and severity.

14
Multi-Selectmedium

Which THREE features are provided by the Splunk ES Incident Review dashboard?

Select 3 answers
A.Status management
B.Risk score threshold configuration
C.Notable event assignment
D.Notable event filtering
E.Threat intelligence feed management
AnswersA, C, D

Analysts update the status of the investigation here.

Why this answer

The Incident Review dashboard is the hub for notable event triage, status tracking, and assignment.

15
MCQhard

If an analyst needs to modify the default retention for the 'risk' index, where should they make this change?

A.ES app settings.
B.Data model acceleration settings.
C.Splunk Index Manager interface.
D.Correlation Search Editor.
AnswerC

The Index Manager is the correct place to adjust retention settings for any index, including the risk index.

Why this answer

Index retention policies are managed in the Splunk index settings (indexes.conf) or via the Manager interface.

16
Multi-Selectmedium

Which TWO methods can be used to suppress unwanted notable events?

Select 2 answers
A.Correlation search suppression
B.Deleting the raw event from the index
C.Changing the user account password
D.Notable event suppression
E.Disabling the data model
AnswersA, D

This allows the search itself to exclude certain patterns.

Why this answer

Notable event suppression and correlation search suppression are the standard ways to manage alert noise.

17
MCQeasy

Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?

A.Notable Event Suppression
B.Case Management
C.Risk Analysis Dashboard
D.Incident Review
AnswerB

Case Management is specifically designed for incident lifecycle tracking.

Why this answer

Case Management provides the structure and tools for incident lifecycle management.

18
MCQmedium

Which data model does the Risk Analysis adaptive response action typically rely upon to enrich events?

A.Vulnerability Data Model
B.Threat Intelligence Data Model
C.Risk Data Model
D.Endpoint Data Model
AnswerC

The Risk data model is the primary model used to store and query risk-related events in Splunk ES.

Why this answer

While it can run on raw events, the Risk Analysis action is often used in correlation searches that monitor data models like 'Network Traffic' or 'Authentication'.

19
Multi-Selecthard

Which THREE settings can be configured within the 'Risk Analysis' adaptive response action?

Select 3 answers
A.CPU core count
B.Risk Message
C.Risk Score
D.Risk Object
E.Network interface speed
AnswersB, C, D

You provide a descriptive message for the risk event.

Why this answer

The action allows configuration of the risk object, score, and message.

20
Multi-Selecthard

Which THREE elements are essential for a well-defined risk-based alert?

Select 3 answers
A.A threshold for notable generation
B.Assignment of a risk score
C.Manual approval for every alert
D.Identification of a risk object
E.Hardware-level encryption
AnswersA, B, D

The threshold determines when risk becomes a notable.

Why this answer

RBA requires identifying the risk object, assigning a score, and using a correlation search to monitor that risk.

21
MCQhard

A correlation search is failing to generate risk events. You check the 'Search Activity' and see that the search is running but returning 0 results. What is the most likely cause?

A.The search logic does not match the data.
B.The Splunk indexer is overloaded.
C.The user does not have permission to write to the risk index.
D.The Risk Analysis action is disabled.
AnswerA

The most common reason for 0 results is a mismatch between the search logic and the indexed data fields.

Why this answer

If the search returns no results, the logic inside the search is likely too restrictive, such as incorrect data model mapping or field names.

22
MCQmedium

During an investigation, you need to group related notables into a single investigation container. Which feature should you use?

A.Splunk Case Management
B.Notable Event Aggregation
C.Notable Event Suppression
D.Incident Review Filters
AnswerA

Case Management allows analysts to create cases and add relevant notable events to them.

Why this answer

In Splunk ES, 'Cases' are the primary mechanism for grouping and managing related notable events during an investigation.

23
MCQhard

When calculating a risk score using the 'sum' aggregation method, what happens if multiple risk events for the same object occur within the same time window?

A.The scores are additive.
B.Only the highest score is kept.
C.The scores are averaged.
D.The risk score is reset to zero.
AnswerA

The 'sum' aggregation logic aggregates individual event scores into a total score.

Why this answer

The 'sum' aggregation method cumulatively adds the risk score of every incident to the total score of the object.

24
MCQeasy

What is the benefit of using the Asset and Identity framework in Splunk ES investigations?

A.It hides false positives.
B.It automatically generates risk scores.
C.It provides context to events.
D.It replaces the need for data models.
AnswerC

Contextual enrichment makes events more actionable.

Why this answer

It provides contextual information (like user departments or host ownership) to notable events, allowing for better prioritization and investigation.

25
MCQhard

You notice that the risk score for an asset is not decaying. Which configuration controls the risk score lifespan?

A.Data model acceleration TTL.
B.Search Scheduler settings.
C.Risk Analysis configuration in ES Settings.
D.Notable event retention settings.
AnswerC

ES settings contain the global configuration for risk scoring and decay.

Why this answer

The 'Risk Analysis' settings in the ES app configuration dictate how long risk scores persist before decaying.

26
MCQhard

You are troubleshooting a scenario where the 'Risk Notable' is not firing as expected. Which log file should you inspect first to confirm if the Risk Analysis action was successfully triggered?

A.correlation_search.log
B.splunkd.log
C.notable_events.log
D.risk_index.log
AnswerB

splunkd.log contains logs for adaptive response executions and scheduling errors.

Why this answer

The splunkd.log file contains internal diagnostic information about adaptive response actions executed by the correlation search scheduler.

27
Multi-Selecthard

Which TWO actions can be taken on a notable event directly from the Incident Review dashboard?

Select 2 answers
A.Change the notable event status
B.Execute adaptive response actions
C.Modify the correlation search code
D.Rebuild the threat intelligence index
E.Delete the underlying index
AnswersA, B

Updating the status is a key part of incident lifecycle management.

Why this answer

Analysts can run adaptive response actions and manage the notable event status directly from this dashboard.

28
MCQmedium

If an analyst wants to see all risk events associated with a specific IP address, which search command is most effective?

A.collect index=risk
B.lookup asset_info
C.tstats count from datamodel=Risk where Risk.src_ip=...
D.search index=risk src_ip=...
AnswerC

tstats is the recommended approach for searching indexed data models.

Why this answer

The 'tstats' command is the most efficient way to query the risk data model for events associated with a specific field value.

29
MCQeasy

In the context of Splunk ES, what is an 'Asset'?

A.A malicious IP address.
B.An entity like a host or server.
C.A saved search report.
D.A notable event.
AnswerB

Assets are entities identified within the environment for risk context.

Why this answer

An asset represents an entity in the environment, such as a host or server, which is stored in the asset and identity framework for context enrichment.

30
MCQhard

An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk events?

A.Risk Analysis Dashboard
B.Security Posture Dashboard
C.Investigation Workbench
D.Incident Review
AnswerA

This dashboard provides a dedicated view for analyzing risk event timelines for specific entities.

Why this answer

The 'Risk Analysis' dashboard displays a timeline and list of events that contributed to an object's current risk score.

31
Multi-Selecteasy

Which TWO areas of the Splunk ES environment are used to manage risk-based alerting configurations?

Select 2 answers
A.Risk Analysis configuration
B.License Master UI
C.Knowledge Object Manager
D.Correlation Search Editor
E.Data Model Acceleration UI
AnswersA, D

This is where global risk scoring and decay settings are defined.

Why this answer

The Correlation Search Editor and the Risk Analysis settings are the core locations for managing RBA.

32
MCQmedium

When investigating a case, where should an analyst document their findings to ensure they are available to other team members?

A.In the 'Comments' section of the Case.
B.In the splunkd.log file.
C.By modifying the correlation search.
D.In the Asset and Identity manager.
AnswerA

The Comments section is designed for team collaboration and case logging.

Why this answer

Case Management supports adding comments or notes to a case to facilitate collaboration.

33
MCQmedium

A security analyst needs to adjust the weight of a specific risk rule. Where should this configuration be modified?

A.Correlation Search Editor
B.Identity Manager
C.Risk Index Configuration
D.Risk Notable Settings
AnswerA

The risk score for a specific rule is typically defined within the 'Risk Analysis' adaptive response action settings in the correlation search.

Why this answer

Risk rules are often defined within the correlation search itself, where the risk score is mapped to the event severity.

34
MCQeasy

You are configuring a new Risk-Based Alerting (RBA) workflow. Which component is responsible for transforming raw logs into risk notables within the Splunk Enterprise Security app?

A.Asset and Identity Framework
B.Risk Analysis Adaptive Response Action
C.Correlation Search Editor
D.Notable Event Suppression
AnswerB

The Risk Analysis action tags the event with risk metadata and writes it to the risk index.

Why this answer

The Risk Analysis adaptive response action is the core mechanism in Splunk ES used to generate risk events from notable events or correlation searches.

35
MCQeasy

Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?

A.It alerts on every single event.
B.It eliminates the need for correlation searches.
C.It focuses on aggregated behavior to reduce noise.
D.It ignores all low-severity events.
AnswerC

RBA aggregates multiple signals to identify higher-confidence threats.

Why this answer

RBA reduces alert fatigue by focusing on aggregated activity rather than single, potentially noisy events.

36
MCQhard

When configuring the 'Risk Analysis' adaptive response, what does the 'risk_score' parameter represent?

A.The severity level of the notable event.
B.The threshold for triggering a notable.
C.The total risk score for the object.
D.The value added to the object's risk score.
AnswerD

The risk_score parameter defines the weight assigned to the specific event triggering the action.

Why this answer

The 'risk_score' is the value assigned to an event to quantify the level of risk associated with that activity.

37
MCQmedium

What is the primary function of the 'Risk Notable' correlation search in Splunk ES?

A.To alert when an object's risk score exceeds a threshold.
B.To clear old risk events from memory.
C.To generate risk events from logs.
D.To update the asset and identity table.
AnswerA

This is the core purpose of the Risk Notable correlation search.

Why this answer

The 'Risk Notable' search monitors the 'risk' index and triggers a notable event when an object's aggregated risk score exceeds a defined threshold.

38
Multi-Selecteasy

Which TWO types of data are commonly enriched by the Asset and Identity framework?

Select 2 answers
A.Host/Asset context
B.Encrypted packet captures
C.User identity information
D.Raw web server application logs
E.System performance statistics
AnswersA, C

Asset context, such as ownership, is added to events.

Why this answer

The framework is primarily used to add context to users and hosts (assets).

Ready to test yourself?

Try a timed practice session using only Investigation And Risk Management questions.