SPLK-5001 · domain
Investigation And Risk Management
Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Investigation And Risk Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Investigation And Risk Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Investigation And Risk Management
Investigation And Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Investigation And Risk Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Investigation And Risk Management questions (38)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are key components of a successful incident investigation workflow in Splunk ES?
Easy2When configuring an 'Adaptive Response' action, what does the 'Notable' action type do?
Hard3Which THREE pieces of information are commonly found in a Splunk ES Case?
Easy4Which TWO factors influence an object's final risk score in Splunk ES?
Hard5An analyst needs to manually add an event to an existing case in Splunk ES. What is the correct procedure?
Medium6Which THREE dashboard categories in Splunk ES are most useful for risk-based investigation?
Medium7Which THREE actions are part of the 'Incident Review' investigation workflow?
Easy8When reviewing an incident, how can an analyst verify if the notable event was generated by a specific correlation search?
Medium9What is the purpose of the 'Investigation Workbench' in Splunk ES?
Easy10When investigating a risk notable, which dashboard in Splunk ES provides a visual representation of the risk contributors for a specific user?
Easy11In the Incident Review dashboard, what does 'Status' represent?
Easy12A customer wants to exclude certain low-fidelity risk events from their Risk Notable correlation search. Where is the best place to define these exclusions?
Medium13Which TWO metrics are tracked in the 'Incident Review' dashboard's 'Notable Event' list?
Medium14Which THREE features are provided by the Splunk ES Incident Review dashboard?
Medium15If an analyst needs to modify the default retention for the 'risk' index, where should they make this change?
Hard16Which TWO methods can be used to suppress unwanted notable events?
Medium17Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?
Easy18Which data model does the Risk Analysis adaptive response action typically rely upon to enrich events?
Medium19Which THREE settings can be configured within the 'Risk Analysis' adaptive response action?
Hard20Which THREE elements are essential for a well-defined risk-based alert?
Hard21A correlation search is failing to generate risk events. You check the 'Search Activity' and see that the search is running but returning 0 results. What is the most likely cause?
Hard22During an investigation, you need to group related notables into a single investigation container. Which feature should you use?
Medium23When calculating a risk score using the 'sum' aggregation method, what happens if multiple risk events for the same object occur within the same time window?
Hard24What is the benefit of using the Asset and Identity framework in Splunk ES investigations?
Easy25You notice that the risk score for an asset is not decaying. Which configuration controls the risk score lifespan?
Hard26You are troubleshooting a scenario where the 'Risk Notable' is not firing as expected. Which log file should you inspect first to confirm if the Risk Analysis action was successfully triggered?
Hard27Which TWO actions can be taken on a notable event directly from the Incident Review dashboard?
Hard28If an analyst wants to see all risk events associated with a specific IP address, which search command is most effective?
Medium29In the context of Splunk ES, what is an 'Asset'?
Easy30An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk events?
Hard31Which TWO areas of the Splunk ES environment are used to manage risk-based alerting configurations?
Easy32When investigating a case, where should an analyst document their findings to ensure they are available to other team members?
Medium33A security analyst needs to adjust the weight of a specific risk rule. Where should this configuration be modified?
Medium34You are configuring a new Risk-Based Alerting (RBA) workflow. Which component is responsible for transforming raw logs into risk notables within the Splunk Enterprise Security app?
Easy35Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?
Easy36When configuring the 'Risk Analysis' adaptive response, what does the 'risk_score' parameter represent?
Hard37What is the primary function of the 'Risk Notable' correlation search in Splunk ES?
Medium38Which TWO types of data are commonly enriched by the Asset and Identity framework?
EasyOther domains
All SPLK-5001 exam domains
Frequently asked questions
- What does the Investigation And Risk Management domain cover on the SPLK-5001 exam?
- Investigation And Risk Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 38 Investigation And Risk Management questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Investigation And Risk Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.