Courseiva

SPLK-5001 · domain

Investigation And Risk Management

Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Investigation And Risk Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

38 questions13 easy13 medium12 hard

Focused practice

Practice Investigation And Risk Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Investigation And Risk Management

Investigation And Risk Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Investigation And Risk Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Investigation And Risk Management questions (38)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are key components of a successful incident investigation workflow in Splunk ES?

Easy
2

When configuring an 'Adaptive Response' action, what does the 'Notable' action type do?

Hard
3

Which THREE pieces of information are commonly found in a Splunk ES Case?

Easy
4

Which TWO factors influence an object's final risk score in Splunk ES?

Hard
5

An analyst needs to manually add an event to an existing case in Splunk ES. What is the correct procedure?

Medium
6

Which THREE dashboard categories in Splunk ES are most useful for risk-based investigation?

Medium
7

Which THREE actions are part of the 'Incident Review' investigation workflow?

Easy
8

When reviewing an incident, how can an analyst verify if the notable event was generated by a specific correlation search?

Medium
9

What is the purpose of the 'Investigation Workbench' in Splunk ES?

Easy
10

When investigating a risk notable, which dashboard in Splunk ES provides a visual representation of the risk contributors for a specific user?

Easy
11

In the Incident Review dashboard, what does 'Status' represent?

Easy
12

A customer wants to exclude certain low-fidelity risk events from their Risk Notable correlation search. Where is the best place to define these exclusions?

Medium
13

Which TWO metrics are tracked in the 'Incident Review' dashboard's 'Notable Event' list?

Medium
14

Which THREE features are provided by the Splunk ES Incident Review dashboard?

Medium
15

If an analyst needs to modify the default retention for the 'risk' index, where should they make this change?

Hard
16

Which TWO methods can be used to suppress unwanted notable events?

Medium
17

Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?

Easy
18

Which data model does the Risk Analysis adaptive response action typically rely upon to enrich events?

Medium
19

Which THREE settings can be configured within the 'Risk Analysis' adaptive response action?

Hard
20

Which THREE elements are essential for a well-defined risk-based alert?

Hard
21

A correlation search is failing to generate risk events. You check the 'Search Activity' and see that the search is running but returning 0 results. What is the most likely cause?

Hard
22

During an investigation, you need to group related notables into a single investigation container. Which feature should you use?

Medium
23

When calculating a risk score using the 'sum' aggregation method, what happens if multiple risk events for the same object occur within the same time window?

Hard
24

What is the benefit of using the Asset and Identity framework in Splunk ES investigations?

Easy
25

You notice that the risk score for an asset is not decaying. Which configuration controls the risk score lifespan?

Hard
26

You are troubleshooting a scenario where the 'Risk Notable' is not firing as expected. Which log file should you inspect first to confirm if the Risk Analysis action was successfully triggered?

Hard
27

Which TWO actions can be taken on a notable event directly from the Incident Review dashboard?

Hard
28

If an analyst wants to see all risk events associated with a specific IP address, which search command is most effective?

Medium
29

In the context of Splunk ES, what is an 'Asset'?

Easy
30

An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk events?

Hard
31

Which TWO areas of the Splunk ES environment are used to manage risk-based alerting configurations?

Easy
32

When investigating a case, where should an analyst document their findings to ensure they are available to other team members?

Medium
33

A security analyst needs to adjust the weight of a specific risk rule. Where should this configuration be modified?

Medium
34

You are configuring a new Risk-Based Alerting (RBA) workflow. Which component is responsible for transforming raw logs into risk notables within the Splunk Enterprise Security app?

Easy
35

Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?

Easy
36

When configuring the 'Risk Analysis' adaptive response, what does the 'risk_score' parameter represent?

Hard
37

What is the primary function of the 'Risk Notable' correlation search in Splunk ES?

Medium
38

Which TWO types of data are commonly enriched by the Asset and Identity framework?

Easy

Frequently asked questions

What does the Investigation And Risk Management domain cover on the SPLK-5001 exam?
Investigation And Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 38 Investigation And Risk Management questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Investigation And Risk Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Investigation And Risk Management Practice Questions