Courseiva

SPLK-5001 · domain

Threat Hunting

Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Threat Hunting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

19 questions4 easy8 medium7 hard

Focused practice

Practice Threat Hunting questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Threat Hunting

Threat Hunting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Threat Hunting exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Threat Hunting questions (19)

Click any question to see the full explanation, or start a practice session above.

1

When drafting a threat hunting playbook, which of the following sections is most critical for ensuring the hunt is repeatable and auditable by other analysts?

Easy
2

Which phase of the proactive threat hunting methodology involves identifying the specific threat actor or technique to be investigated?

Easy
3

You are investigating a potential beaconing pattern. You have identified a suspect destination IP. Which SPL command sequence is most appropriate to calculate the frequency of connections to this IP to validate the beaconing hypothesis?

Hard
4

When designing a threat hunting playbook, which TWO components must be included to ensure the hunt is actionable?

Medium
5

An attacker has cleared the Windows Event Logs to hide their tracks. You are hunting for this activity. Which Event ID in the System log indicates that the log service was stopped or cleared?

Hard
6

You are hunting for anomalous PowerShell activity. Which THREE indicators or behaviors should you look for in your Splunk data?

Hard
7

When utilizing the Splunk Common Information Model (CIM), which field name is standard for identifying the destination IP address across different data sources?

Hard
8

Which TWO actions should be performed during the 'Data Preparation' phase of a threat hunt to ensure accurate results?

Medium
9

In a threat hunting workflow, what is the primary purpose of a 'Lookback' period?

Easy
10

You are hunting for evidence of credential dumping. You have access to Sysmon logs. Which EventCode should be the primary focus for detecting memory access to lsass.exe?

Medium
11

Which THREE techniques can be used in Splunk to reduce the noise of false positives during a threat hunt?

Hard
12

You are conducting a hunt for unauthorized remote access tools. Which Splunk command is most effective for identifying processes that are running from unusual directories (e.g., AppData, Temp)?

Medium
13

Which Splunk feature allows an analyst to save a specific search query, parameterize it with variables, and reuse it across different time ranges and entities?

Easy
14

You are investigating a suspicious PowerShell script. You suspect the script is using Base64 encoding. Which SPL function can you use to decode the string within Splunk?

Medium
15

You are performing a hypothesis-driven hunt and suspect that an attacker is using lateral movement via WMI. Which command in Splunk would best assist in identifying anomalous process creation events associated with WMI (wmiprvse.exe) spawning shells?

Medium
16

You are analyzing a data model using tstats. You need to identify rare process executions across your environment. Which command structure provides the most performance-optimized result?

Hard
17

You suspect an attacker is using 'living-off-the-land' (LotL) techniques. Which Sysmon event should you analyze to see command-line arguments of suspicious utilities?

Medium
18

When hunting for lateral movement, which THREE data sources are most valuable for correlation?

Hard
19

Which TWO Splunk features are best for automating the execution of recurring threat hunts?

Medium

Frequently asked questions

What does the Threat Hunting domain cover on the SPLK-5001 exam?
Threat Hunting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 19 Threat Hunting questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Threat Hunting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
splunk-cybersec SPLUNK-CYBERSEC threat hunting Practice Questions