Courseiva

SPLK-5001 · domain

Threat And Attack Types

Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Threat And Attack Types practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

39 questions12 easy14 medium13 hard

Focused practice

Practice Threat And Attack Types questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Threat And Attack Types

Threat And Attack Types questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat And Attack Types exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Threat And Attack Types questions (39)

Click any question to see the full explanation, or start a practice session above.

1

An attacker is using a technique that involves 'living off the land' by utilizing legitimate system tools. Which data model is most effective to monitor these tools?

Hard
2

An analyst wants to investigate a suspicious email attachment. Which Splunk ES notable event field is most effective for pivoting to the 'File' domain investigation dashboard?

Easy
3

You are investigating a user who has triggered multiple high-risk alerts. Where in Splunk ES can you view the historical risk score progression for this specific user?

Hard
4

Which THREE of the following data sources are most valuable for detecting an insider threat?

Medium
5

A user account is exhibiting signs of being compromised. Where can you find the user's recent login history in Splunk ES?

Easy
6

You need to verify if an external IP address is a known malicious TOR exit node. Which Splunk ES feature should you use?

Medium
7

What is the primary function of the 'Incident Review' dashboard in Splunk ES?

Easy
8

You notice a system process attempting to connect to a suspicious external domain. Which CIM data model would contain this network connection information?

Easy
9

Which Splunk ES component would you use to define a new correlation rule based on a custom blacklist of domains?

Easy
10

An attacker is using a technique to hide in plain sight by renaming a common system process. Which data model is most suitable for comparing process names against known good paths?

Hard
11

An attacker is attempting to use a 'Pass-the-Hash' technique. Which authentication log event code in Windows (Event ID 4624) should you look for to detect this?

Medium
12

Where do you go in Splunk ES to adjust the sensitivity (risk score) of a specific correlation search?

Easy
13

Which THREE of the following components are part of the 'Endpoint' data model?

Medium
14

You are investigating a potential insider threat involving unauthorized data exfiltration. Which Splunk ES feature allows you to correlate multiple events occurring over a long duration to a single entity?

Medium
15

Which THREE of the following are common indicators that a host has been infected with malware?

Hard
16

You want to visualize the geographic origin of incoming connection attempts to identify potentially malicious traffic. Which dashboard is most appropriate?

Medium
17

Which TWO of the following are common types of social engineering?

Medium
18

An attacker is using PowerShell to obfuscate their activities. Which data model is most appropriate for searching for encoded PowerShell commands?

Medium
19

Which TWO of the following are ways to verify if a file hash is truly malicious within Splunk ES?

Hard
20

Which Splunk ES dashboard allows an analyst to see a summary of all active notable events currently requiring investigation?

Easy
21

A phishing campaign is targeting your organization. Which Splunk ES module is best suited to track the delivery of the malicious email URLs?

Easy
22

Which TWO of the following are examples of reconnaissance techniques used by attackers?

Easy
23

Which TWO of the following are valid methods to mitigate an insider threat within Splunk ES?

Medium
24

You notice a high volume of traffic from an internal workstation to a non-standard port on an external server. Which search helps identify the frequency of this connection?

Hard
25

You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?

Medium
26

A SOC analyst observes an unusual spike in failed login attempts followed by a successful login from a new IP address. Which Splunk Enterprise Security dashboard should the analyst check to confirm if this is a potential brute-force attack?

Easy
27

A malware infection is suspected on a host. You notice traffic on port 445. Which Splunk ES correlation search should be prioritized to investigate lateral movement?

Hard
28

Which THREE of the following fields are required for mapping data to the 'Authentication' CIM data model?

Hard
29

Which THREE of the following are benefits of using Risk-Based Alerting (RBA) in Splunk ES?

Hard
30

An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?

Hard
31

Which dashboard provides a summary of all assets categorized by their criticality within the organization?

Medium
32

Which TWO of the following are key components of the Splunk ES Threat Intelligence framework?

Easy
33

An analyst identifies a command-and-control (C2) beaconing pattern. Which search command would be best used to identify the frequency of connections to a specific domain?

Medium
34

Which TWO of the following are primary indicators of a phishing attack that you should look for in email logs?

Easy
35

An attacker has modified the registry to ensure persistence. Which Splunk ES data model tracks Windows registry changes?

Hard
36

You need to ensure that your Splunk ES environment is properly ingesting threat intelligence data. Where can you confirm that threat sources are active?

Hard
37

You are auditing logs and find that a user has modified an audit policy using 'auditpol.exe'. Which Splunk CIM data model should contain this information?

Hard
38

Which THREE of the following data models are critical for monitoring lateral movement within a network?

Medium
39

You need to correlate a VPN login with a subsequent file access on an internal server. Which Splunk ES feature helps you link these disparate events?

Medium

Frequently asked questions

What does the Threat And Attack Types domain cover on the SPLK-5001 exam?
Threat And Attack Types questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 39 Threat And Attack Types questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Threat And Attack Types questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
splunk-cybersec SPLUNK-CYBERSEC threat and attack types Practice Questions