Exam SPLK-5002 Topic 3 Question 55 Discussion
Actual exam question for Splunk's SPLK-5002 exam
Question #: 55
Topic #: 3
Question #: 55
Topic #: 3
An engineer has been asked to build a new dashboard after an increase in login failures across the organization ' s Microsoft Azure domain. They need to construct a search to only display failed logins for their Azure Active Directory users and create a visualization that will help quickly identify failed logins that originate outside of North America. Which search and visualization type combination will achieve this?
Suggested Answer: D Vote an answer
The required combination must satisfy two independent requirements : restrict the dataset to failed Azure Active Directory authentication activity and represent the origin of those events geographically. Option D provides that combination by selecting the failure-oriented Azure AD sign-in data and using geographic- coordinate information with a Cluster Map .
A geographic cluster visualization is appropriate when individual events contain point locations such as latitude and longitude. Multiple sign-in failures originating from the same geographic area can then be grouped visually, making concentrations outside the expected operating region-here, North America- immediately apparent. This is particularly useful for authentication monitoring because a raw table of IP addresses does not provide the same rapid geographic interpretation.
The search must also distinguish failures from successful authentication. Merely plotting all sign-ins would allow large quantities of legitimate activity to obscure the specific anomalous behavior being investigated.
Conversely, choosing an inappropriate geographic visualization for point-coordinate data would not provide the intended presentation.
Study Guide topics: Azure AD authentication data, failed-login filtering, geospatial enrichment, geographic dashboards, Cluster Map visualization, security analytics.
A geographic cluster visualization is appropriate when individual events contain point locations such as latitude and longitude. Multiple sign-in failures originating from the same geographic area can then be grouped visually, making concentrations outside the expected operating region-here, North America- immediately apparent. This is particularly useful for authentication monitoring because a raw table of IP addresses does not provide the same rapid geographic interpretation.
The search must also distinguish failures from successful authentication. Merely plotting all sign-ins would allow large quantities of legitimate activity to obscure the specific anomalous behavior being investigated.
Conversely, choosing an inappropriate geographic visualization for point-coordinate data would not provide the intended presentation.
Study Guide topics: Azure AD authentication data, failed-login filtering, geospatial enrichment, geographic dashboards, Cluster Map visualization, security analytics.
by Leif at Oct 07, 2026, 03:24 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).