Practice SPLK-5001 Threat And Attack Types questions with full explanations on every answer.
Start practicing
Threat And Attack Types — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are investigating a potential insider threat involving unauthorized data exfiltration. Which Splunk ES feature allows you to correlate multiple events occurring over a long duration to a single entity?
2A SOC analyst observes an unusual spike in failed login attempts followed by a successful login from a new IP address. Which Splunk Enterprise Security dashboard should the analyst check to confirm if this is a potential brute-force attack?
3A phishing campaign is targeting your organization. Which Splunk ES module is best suited to track the delivery of the malicious email URLs?
4You need to verify if an external IP address is a known malicious TOR exit node. Which Splunk ES feature should you use?
5An analyst wants to investigate a suspicious email attachment. Which Splunk ES notable event field is most effective for pivoting to the 'File' domain investigation dashboard?
6You are auditing logs and find that a user has modified an audit policy using 'auditpol.exe'. Which Splunk CIM data model should contain this information?
7A malware infection is suspected on a host. You notice traffic on port 445. Which Splunk ES correlation search should be prioritized to investigate lateral movement?
8An analyst identifies a command-and-control (C2) beaconing pattern. Which search command would be best used to identify the frequency of connections to a specific domain?
9You are investigating a user who has triggered multiple high-risk alerts. Where in Splunk ES can you view the historical risk score progression for this specific user?
10Which Splunk ES dashboard allows an analyst to see a summary of all active notable events currently requiring investigation?
11You need to ensure that your Splunk ES environment is properly ingesting threat intelligence data. Where can you confirm that threat sources are active?
12An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?
13You notice a system process attempting to connect to a suspicious external domain. Which CIM data model would contain this network connection information?
14An attacker is using PowerShell to obfuscate their activities. Which data model is most appropriate for searching for encoded PowerShell commands?
15An attacker is attempting to use a 'Pass-the-Hash' technique. Which authentication log event code in Windows (Event ID 4624) should you look for to detect this?
16What is the primary function of the 'Incident Review' dashboard in Splunk ES?
17Which Splunk ES component would you use to define a new correlation rule based on a custom blacklist of domains?
18You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?
19An attacker is using a technique to hide in plain sight by renaming a common system process. Which data model is most suitable for comparing process names against known good paths?
20You want to visualize the geographic origin of incoming connection attempts to identify potentially malicious traffic. Which dashboard is most appropriate?
21You notice a high volume of traffic from an internal workstation to a non-standard port on an external server. Which search helps identify the frequency of this connection?
22You need to correlate a VPN login with a subsequent file access on an internal server. Which Splunk ES feature helps you link these disparate events?
23An attacker has modified the registry to ensure persistence. Which Splunk ES data model tracks Windows registry changes?
24Where do you go in Splunk ES to adjust the sensitivity (risk score) of a specific correlation search?
25Which TWO of the following are primary indicators of a phishing attack that you should look for in email logs?
26An attacker is using a technique that involves 'living off the land' by utilizing legitimate system tools. Which data model is most effective to monitor these tools?
27A user account is exhibiting signs of being compromised. Where can you find the user's recent login history in Splunk ES?
28Which dashboard provides a summary of all assets categorized by their criticality within the organization?
29Which THREE of the following data models are critical for monitoring lateral movement within a network?
30Which TWO of the following are valid methods to mitigate an insider threat within Splunk ES?
31Which THREE of the following are common indicators that a host has been infected with malware?
32Which TWO of the following are key components of the Splunk ES Threat Intelligence framework?
33Which TWO of the following are common types of social engineering?
34Which TWO of the following are examples of reconnaissance techniques used by attackers?
35Which THREE of the following are benefits of using Risk-Based Alerting (RBA) in Splunk ES?
36Which THREE of the following data sources are most valuable for detecting an insider threat?
37Which THREE of the following fields are required for mapping data to the 'Authentication' CIM data model?
38Which THREE of the following components are part of the 'Endpoint' data model?
39Which TWO of the following are ways to verify if a file hash is truly malicious within Splunk ES?
The Threat And Attack Types domain covers the key concepts tested in this area of the SPLK-5001 exam blueprint published by Splunk. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SPLK-5001 domains — no account required.
The Courseiva SPLK-5001 question bank contains 39 questions in the Threat And Attack Types domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Threat And Attack Types domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included