SPLK-5001 · domain
Threat Hunting
Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) Threat Hunting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Threat Hunting questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Threat Hunting
Threat Hunting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Threat Hunting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Threat Hunting questions (19)
Click any question to see the full explanation, or start a practice session above.
When drafting a threat hunting playbook, which of the following sections is most critical for ensuring the hunt is repeatable and auditable by other analysts?
Easy2Which phase of the proactive threat hunting methodology involves identifying the specific threat actor or technique to be investigated?
Easy3You are investigating a potential beaconing pattern. You have identified a suspect destination IP. Which SPL command sequence is most appropriate to calculate the frequency of connections to this IP to validate the beaconing hypothesis?
Hard4When designing a threat hunting playbook, which TWO components must be included to ensure the hunt is actionable?
Medium5An attacker has cleared the Windows Event Logs to hide their tracks. You are hunting for this activity. Which Event ID in the System log indicates that the log service was stopped or cleared?
Hard6You are hunting for anomalous PowerShell activity. Which THREE indicators or behaviors should you look for in your Splunk data?
Hard7When utilizing the Splunk Common Information Model (CIM), which field name is standard for identifying the destination IP address across different data sources?
Hard8Which TWO actions should be performed during the 'Data Preparation' phase of a threat hunt to ensure accurate results?
Medium9In a threat hunting workflow, what is the primary purpose of a 'Lookback' period?
Easy10You are hunting for evidence of credential dumping. You have access to Sysmon logs. Which EventCode should be the primary focus for detecting memory access to lsass.exe?
Medium11Which THREE techniques can be used in Splunk to reduce the noise of false positives during a threat hunt?
Hard12You are conducting a hunt for unauthorized remote access tools. Which Splunk command is most effective for identifying processes that are running from unusual directories (e.g., AppData, Temp)?
Medium13Which Splunk feature allows an analyst to save a specific search query, parameterize it with variables, and reuse it across different time ranges and entities?
Easy14You are investigating a suspicious PowerShell script. You suspect the script is using Base64 encoding. Which SPL function can you use to decode the string within Splunk?
Medium15You are performing a hypothesis-driven hunt and suspect that an attacker is using lateral movement via WMI. Which command in Splunk would best assist in identifying anomalous process creation events associated with WMI (wmiprvse.exe) spawning shells?
Medium16You are analyzing a data model using tstats. You need to identify rare process executions across your environment. Which command structure provides the most performance-optimized result?
Hard17You suspect an attacker is using 'living-off-the-land' (LotL) techniques. Which Sysmon event should you analyze to see command-line arguments of suspicious utilities?
Medium18When hunting for lateral movement, which THREE data sources are most valuable for correlation?
Hard19Which TWO Splunk features are best for automating the execution of recurring threat hunts?
MediumOther domains
All SPLK-5001 exam domains
Frequently asked questions
- What does the Threat Hunting domain cover on the SPLK-5001 exam?
- Threat Hunting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 19 Threat Hunting questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Threat Hunting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.