Sample questions
Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) practice questions
Which THREE of the following are common phases defined in the Cyber Kill Chain model?
You are mapping incoming alerts to the MITRE ATT&CK framework within the Splunk Enterprise Security (ES) Incident Review dashboard. Which attribute mapping ensures that your TTP-ba…
Which THREE of the following represent the categories of threat intelligence that can be managed within the Splunk Enterprise Security 'Threat Intelligence' framework?
You are integrating Splunk with the CIS Benchmarks. Which TWO of the following configurations are necessary to report on 'Secure Configuration' of endpoints?
Which phase of the Cyber Kill Chain is most effectively mitigated by implementing strict egress filtering on your firewall?
You are auditing your environment against the NIST CSF 'Detect' function. Which TWO of the following Splunk ES features provide the necessary visibility?
Which of the following is considered 'Reconnaissance' in the Cyber Kill Chain?
Which THREE of the following are recognized components of the NIST Cybersecurity Framework (CSF) Core functions?
Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?
An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk eve…
Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?
An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?
When aligning Splunk Enterprise Security with the NIST CSF 'Recover' function, which feature is most applicable for documenting the incident response process?
Your organization is adopting the CIS Controls v8. You are using Splunk to track 'Inventory and Control of Enterprise Assets'. Which Data Model is essential for this visibility?
You are configuring the Splunk Security Essentials (SSE) app to align with the NIST CSF framework. You want to prioritize your detection development based on the most critical gaps…
An analyst needs to correlate an alert with the 'Delivery' phase of the Cyber Kill Chain. Which data source should be most prioritized for this specific stage?
A security analyst notices an alert from the 'MITRE ATT&CK - Initial Access' tactic. Which data source should be primary for investigating this alert?
Which of the following best describes the goal of the 'Exploitation' phase in the Cyber Kill Chain?
You are configuring CIS Benchmarks in Splunk for your Linux environment. Which tool/app is the standard for ingesting and reporting these compliance checks?
You are troubleshooting an 'Adaptive Response' action that is failing to execute on a remote device. What should you check first?
Which field is mandatory for an event to be correctly categorized by the Common Information Model (CIM) 'Network Traffic' data model?
You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?
You are reviewing a Splunk Enterprise Security alert mapped to the MITRE ATT&CK technique 'T1059.001 (PowerShell)'. Which search command would best identify the use of obfuscated P…
You are performing a hypothesis-driven hunt and suspect that an attacker is using lateral movement via WMI. Which command in Splunk would best assist in identifying anomalous proce…