SPLK-5001 · domain
Threat And Attack Types
Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Threat And Attack Types practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Threat And Attack Types questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Threat And Attack Types
Threat And Attack Types questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Threat And Attack Types exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Threat And Attack Types questions (39)
Click any question to see the full explanation, or start a practice session above.
An attacker is using a technique that involves 'living off the land' by utilizing legitimate system tools. Which data model is most effective to monitor these tools?
Hard2An analyst wants to investigate a suspicious email attachment. Which Splunk ES notable event field is most effective for pivoting to the 'File' domain investigation dashboard?
Easy3You are investigating a user who has triggered multiple high-risk alerts. Where in Splunk ES can you view the historical risk score progression for this specific user?
Hard4Which THREE of the following data sources are most valuable for detecting an insider threat?
Medium5A user account is exhibiting signs of being compromised. Where can you find the user's recent login history in Splunk ES?
Easy6You need to verify if an external IP address is a known malicious TOR exit node. Which Splunk ES feature should you use?
Medium7What is the primary function of the 'Incident Review' dashboard in Splunk ES?
Easy8You notice a system process attempting to connect to a suspicious external domain. Which CIM data model would contain this network connection information?
Easy9Which Splunk ES component would you use to define a new correlation rule based on a custom blacklist of domains?
Easy10An attacker is using a technique to hide in plain sight by renaming a common system process. Which data model is most suitable for comparing process names against known good paths?
Hard11An attacker is attempting to use a 'Pass-the-Hash' technique. Which authentication log event code in Windows (Event ID 4624) should you look for to detect this?
Medium12Where do you go in Splunk ES to adjust the sensitivity (risk score) of a specific correlation search?
Easy13Which THREE of the following components are part of the 'Endpoint' data model?
Medium14You are investigating a potential insider threat involving unauthorized data exfiltration. Which Splunk ES feature allows you to correlate multiple events occurring over a long duration to a single entity?
Medium15Which THREE of the following are common indicators that a host has been infected with malware?
Hard16You want to visualize the geographic origin of incoming connection attempts to identify potentially malicious traffic. Which dashboard is most appropriate?
Medium17Which TWO of the following are common types of social engineering?
Medium18An attacker is using PowerShell to obfuscate their activities. Which data model is most appropriate for searching for encoded PowerShell commands?
Medium19Which TWO of the following are ways to verify if a file hash is truly malicious within Splunk ES?
Hard20Which Splunk ES dashboard allows an analyst to see a summary of all active notable events currently requiring investigation?
Easy21A phishing campaign is targeting your organization. Which Splunk ES module is best suited to track the delivery of the malicious email URLs?
Easy22Which TWO of the following are examples of reconnaissance techniques used by attackers?
Easy23Which TWO of the following are valid methods to mitigate an insider threat within Splunk ES?
Medium24You notice a high volume of traffic from an internal workstation to a non-standard port on an external server. Which search helps identify the frequency of this connection?
Hard25You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?
Medium26A SOC analyst observes an unusual spike in failed login attempts followed by a successful login from a new IP address. Which Splunk Enterprise Security dashboard should the analyst check to confirm if this is a potential brute-force attack?
Easy27A malware infection is suspected on a host. You notice traffic on port 445. Which Splunk ES correlation search should be prioritized to investigate lateral movement?
Hard28Which THREE of the following fields are required for mapping data to the 'Authentication' CIM data model?
Hard29Which THREE of the following are benefits of using Risk-Based Alerting (RBA) in Splunk ES?
Hard30An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?
Hard31Which dashboard provides a summary of all assets categorized by their criticality within the organization?
Medium32Which TWO of the following are key components of the Splunk ES Threat Intelligence framework?
Easy33An analyst identifies a command-and-control (C2) beaconing pattern. Which search command would be best used to identify the frequency of connections to a specific domain?
Medium34Which TWO of the following are primary indicators of a phishing attack that you should look for in email logs?
Easy35An attacker has modified the registry to ensure persistence. Which Splunk ES data model tracks Windows registry changes?
Hard36You need to ensure that your Splunk ES environment is properly ingesting threat intelligence data. Where can you confirm that threat sources are active?
Hard37You are auditing logs and find that a user has modified an audit policy using 'auditpol.exe'. Which Splunk CIM data model should contain this information?
Hard38Which THREE of the following data models are critical for monitoring lateral movement within a network?
Medium39You need to correlate a VPN login with a subsequent file access on an internal server. Which Splunk ES feature helps you link these disparate events?
MediumOther domains
All SPLK-5001 exam domains
Frequently asked questions
- What does the Threat And Attack Types domain cover on the SPLK-5001 exam?
- Threat And Attack Types questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 39 Threat And Attack Types questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Threat And Attack Types questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.