SPLK-5001 · domain
troubleshooting
Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (203)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are key components of a successful incident investigation workflow in Splunk ES?
Easy2Which THREE tasks are performed within the 'CIM Setup' interface?
Medium3What is the purpose of the 'head' command?
Easy4An attacker is using a technique that involves 'living off the land' by utilizing legitimate system tools. Which data model is most effective to monitor these tools?
Hard5You are configuring the Splunk Security Essentials (SSE) app to align with the NIST CSF framework. You want to prioritize your detection development based on the most critical gaps. Which action should you take?
Hard6You need to ensure that only authorized users can view certain sensitive notable events. How do you implement this in Splunk ES?
Medium7When drafting a threat hunting playbook, which of the following sections is most critical for ensuring the hunt is repeatable and auditable by other analysts?
Easy8A security engineer is configuring a new correlation search that needs to correlate data across two different indexes. Which Splunk ES feature allows for efficient correlation across large datasets?
Hard9Which TWO of the following commands are used for data transformation or enrichment?
Medium10Which phase of the proactive threat hunting methodology involves identifying the specific threat actor or technique to be investigated?
Easy11A security analyst notices an alert from the 'MITRE ATT&CK - Initial Access' tactic. Which data source should be primary for investigating this alert?
Medium12Which character acts as a wildcard in a search string?
Easy13A user reports that a specific dashboard panel is timing out. After checking the search job, you notice it is scanning too much data. Which configuration should you adjust?
Hard14You are investigating a potential beaconing pattern. You have identified a suspect destination IP. Which SPL command sequence is most appropriate to calculate the frequency of connections to this IP to validate the beaconing hypothesis?
Hard15When configuring an 'Adaptive Response' action, what does the 'Notable' action type do?
Hard16Which Splunk Enterprise Security feature allows you to manage the lifecycle of a notable event?
Easy17An analyst wants to investigate a suspicious email attachment. Which Splunk ES notable event field is most effective for pivoting to the 'File' domain investigation dashboard?
Easy18You are using a subsearch to find 'dest_ip' values that appeared in a 'failed_login' search. What is a common limitation of subsearches that you must consider?
Hard19Which THREE pieces of information are commonly found in a Splunk ES Case?
Easy20Which TWO factors influence an object's final risk score in Splunk ES?
Hard21Which TWO commands provide information about the fields present in the events?
Medium22Which dashboard in Splunk ES provides a high-level view of threats and vulnerabilities mapped to the MITRE ATT&CK framework?
Medium23An analyst needs to manually add an event to an existing case in Splunk ES. What is the correct procedure?
Medium24Which THREE dashboard categories in Splunk ES are most useful for risk-based investigation?
Medium25Which THREE components are required for an Adaptive Response action to function?
Medium26You are creating a custom Adaptive Response action. The action requires a Python script. Where must this script be placed for the Splunk instance to execute it?
Hard27You are creating a custom correlation search that triggers a notable event. How do you ensure the notable event maintains the correct 'owner' assignment when the search triggers for multiple distinct users?
Hard28When designing a threat hunting playbook, which TWO components must be included to ensure the hunt is actionable?
Medium29An attacker has cleared the Windows Event Logs to hide their tracks. You are hunting for this activity. Which Event ID in the System log indicates that the log service was stopped or cleared?
Hard30You are investigating a user who has triggered multiple high-risk alerts. Where in Splunk ES can you view the historical risk score progression for this specific user?
Hard31Which THREE actions are part of the 'Incident Review' investigation workflow?
Easy32Which THREE of the following data sources are most valuable for detecting an insider threat?
Medium33What is the effect of changing the 'Retention Period' in the Enterprise Security app settings?
Medium34You are hunting for anomalous PowerShell activity. Which THREE indicators or behaviors should you look for in your Splunk data?
Hard35Which command is used to calculate the 'count' of events and concurrently keep the original 'raw' text?
Hard36When reviewing an incident, how can an analyst verify if the notable event was generated by a specific correlation search?
Medium37You have a field 'raw_data' containing JSON. How do you extract fields from it within your SPL search?
Hard38What is the purpose of the 'map' command in complex searches?
Hard39What is the purpose of the 'Investigation Workbench' in Splunk ES?
Easy40When investigating a risk notable, which dashboard in Splunk ES provides a visual representation of the risk contributors for a specific user?
Easy41What is the purpose of the 'Assets and Identities' framework in Splunk ES?
Medium42Which THREE of the following are necessary prerequisites for ensuring a new data source is correctly utilized by the ES 'Access' data model?
Hard43Which THREE of the following represent the categories of threat intelligence that can be managed within the Splunk Enterprise Security 'Threat Intelligence' framework?
Medium44A user account is exhibiting signs of being compromised. Where can you find the user's recent login history in Splunk ES?
Easy45Which TWO actions should be taken if a correlation search is consuming too many system resources?
Hard46You are configuring Splunk Enterprise Security to monitor for MITRE ATT&CK 'Persistence' techniques. Which TWO data sources provide the highest fidelity logs for detecting registry-based persistence?
Hard47In the Incident Review dashboard, what does 'Status' represent?
Easy48Which command is used to visualize data in a time-series chart?
Easy49You want to find the total count of events per hour over the last week. Which command sequence is most efficient?
Medium50When using the 'Risk Analysis' framework in Splunk ES, what is the primary benefit of assigning a 'Risk Object'?
Medium51A customer wants to exclude certain low-fidelity risk events from their Risk Notable correlation search. Where is the best place to define these exclusions?
Medium52You need to verify if an external IP address is a known malicious TOR exit node. Which Splunk ES feature should you use?
Medium53What is the primary function of the 'Incident Review' dashboard in Splunk ES?
Easy54When utilizing the Splunk Common Information Model (CIM), which field name is standard for identifying the destination IP address across different data sources?
Hard55You want to dynamically update a lookup table with new indicators of compromise (IOCs) found during your search. Which command is used for this?
Hard56You notice a system process attempting to connect to a suspicious external domain. Which CIM data model would contain this network connection information?
Easy57What is the result of using 'bin _time span=1d'?
Medium58Which Splunk ES component would you use to define a new correlation rule based on a custom blacklist of domains?
Easy59Which TWO actions should be performed during the 'Data Preparation' phase of a threat hunt to ensure accurate results?
Medium60Which TWO metrics are tracked in the 'Incident Review' dashboard's 'Notable Event' list?
Medium61An attacker is using a technique to hide in plain sight by renaming a common system process. Which data model is most suitable for comparing process names against known good paths?
Hard62Which THREE features are provided by the Splunk ES Incident Review dashboard?
Medium63Which field is mandatory for an event to be correctly categorized by the Common Information Model (CIM) 'Network Traffic' data model?
Medium64An attacker is attempting to use a 'Pass-the-Hash' technique. Which authentication log event code in Windows (Event ID 4624) should you look for to detect this?
Medium65Which THREE things are required for Splunk Enterprise Security to provide meaningful security insights?
Easy66If an analyst needs to modify the default retention for the 'risk' index, where should they make this change?
Hard67Where do you go in Splunk ES to adjust the sensitivity (risk score) of a specific correlation search?
Easy68Which THREE of the following components are part of the 'Endpoint' data model?
Medium69You are investigating a potential insider threat involving unauthorized data exfiltration. Which Splunk ES feature allows you to correlate multiple events occurring over a long duration to a single entity?
Medium70You are using 'lookup' to add user info. What happens if the common field doesn't exist in the lookup file?
Medium71Which TWO methods can be used to suppress unwanted notable events?
Medium72Which TWO factors are critical for effective Asset and Identity enrichment?
Medium73You are configuring a 'Notable Event' to use a specific 'Drilldown' link. What syntax is used to pass fields from the event into the URL?
Hard74When aligning Splunk Enterprise Security with the NIST CSF 'Recover' function, which feature is most applicable for documenting the incident response process?
Hard75Which TWO factors directly impact the urgency of a notable event in Splunk ES?
Hard76Which TWO commands require a grouping field to function correctly?
Medium77Which THREE of the following are common indicators that a host has been infected with malware?
Hard78In a threat hunting workflow, what is the primary purpose of a 'Lookback' period?
Easy79Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?
Easy80You are hunting for evidence of credential dumping. You have access to Sysmon logs. Which EventCode should be the primary focus for detecting memory access to lsass.exe?
Medium81When onboarding a new firewall source, you notice that the data is not populating the 'Network Traffic' data model. What is the most efficient first step to troubleshoot the CIM mapping?
Medium82How can you ensure that a search field is only treated as a number for calculation purposes?
Hard83You want to visualize the geographic origin of incoming connection attempts to identify potentially malicious traffic. Which dashboard is most appropriate?
Medium84Which THREE of the following are valid uses of the 'eval' command?
Hard85You are mapping incoming alerts to the MITRE ATT&CK framework within the Splunk Enterprise Security (ES) Incident Review dashboard. Which attribute mapping ensures that your TTP-based notable events correctly reflect the adversary behavior?
Medium86Which data model does the Risk Analysis adaptive response action typically rely upon to enrich events?
Medium87You want to calculate the standard deviation of 'response_time' per 'server'. Which command is correct?
Medium88Which THREE diagnostic tools or logs are useful for troubleshooting a malfunctioning correlation search?
Hard89Which THREE settings can be configured within the 'Risk Analysis' adaptive response action?
Hard90Which Splunk ES dashboard allows you to view and manage active threat intelligence feeds?
Easy91You are troubleshooting an 'Adaptive Response' action that is failing to execute on a remote device. What should you check first?
Medium92Which TWO of the following are common types of social engineering?
Medium93An attacker is using PowerShell to obfuscate their activities. Which data model is most appropriate for searching for encoded PowerShell commands?
Medium94You are performing a search and want to ensure the subsearch runs against a specific time range relative to the main search. Which command/option achieves this?
Medium95Which THREE elements are essential for a well-defined risk-based alert?
Hard96You want to use the 'eval' command to create a new field 'is_critical' that is 'yes' if 'severity' is 'high' or 'critical', and 'no' otherwise. Which syntax is correct?
Medium97A correlation search is failing to generate risk events. You check the 'Search Activity' and see that the search is running but returning 0 results. What is the most likely cause?
Hard98Which THREE of the following are common phases defined in the Cyber Kill Chain model?
Medium99When a notable event is generated, where does the 'Risk Score' value originate?
Medium100Which TWO of the following are ways to verify if a file hash is truly malicious within Splunk ES?
Hard101During an investigation, you need to group related notables into a single investigation container. Which feature should you use?
Medium102Which Splunk ES dashboard allows an analyst to see a summary of all active notable events currently requiring investigation?
Easy103A phishing campaign is targeting your organization. Which Splunk ES module is best suited to track the delivery of the malicious email URLs?
Easy104Which TWO of the following are examples of reconnaissance techniques used by attackers?
Easy105You need to ensure that the 'Threat Intelligence' framework periodically updates. Where do you configure the update interval?
Hard106Which THREE techniques can be used in Splunk to reduce the noise of false positives during a threat hunt?
Hard107You are conducting a hunt for unauthorized remote access tools. Which Splunk command is most effective for identifying processes that are running from unusual directories (e.g., AppData, Temp)?
Medium108Which THREE of the following are valid search operators?
Hard109Which TWO ways can you enrich events with threat intelligence in Splunk ES?
Hard110You are onboarding a new Windows Event Log source using the Splunk Universal Forwarder. To ensure the data conforms to the Splunk Common Information Model (CIM) for the Authentication data model, where should you primarily configure the sourcetype?
Medium111Which search command is used to join threat intelligence data with your local search results?
Easy112Which TWO of the following are valid methods to mitigate an insider threat within Splunk ES?
Medium113Which THREE of the following represent valid ways to use the 'lookup' command?
Hard114Which Splunk feature allows an analyst to save a specific search query, parameterize it with variables, and reuse it across different time ranges and entities?
Easy115When calculating a risk score using the 'sum' aggregation method, what happens if multiple risk events for the same object occur within the same time window?
Hard116You notice a high volume of traffic from an internal workstation to a non-standard port on an external server. Which search helps identify the frequency of this connection?
Hard117You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?
Medium118When using the Splunk Enterprise Security 'Threat Intelligence' framework, which file type is used to import custom STIX/TAXII threat feeds to align with the MITRE ATT&CK framework?
Hard119You are investigating a potential data exfiltration event. You have a lookup file called 'authorized_servers.csv' containing a field 'ip_address'. You want to find all connections to IPs not in this list. Which command fulfills this?
Medium120You are investigating a suspicious PowerShell script. You suspect the script is using Base64 encoding. Which SPL function can you use to decode the string within Splunk?
Medium121What is the primary function of the 'Notable Event Suppression' feature?
Easy122You are reviewing a Splunk Enterprise Security alert mapped to the MITRE ATT&CK technique 'T1059.001 (PowerShell)'. Which search command would best identify the use of obfuscated PowerShell commands?
Hard123What is the benefit of using the Asset and Identity framework in Splunk ES investigations?
Easy124In Splunk ES, where can you manage the 'Risk Threshold' for triggering a Notable Event based on aggregate risk scores?
Easy125You are performing a hypothesis-driven hunt and suspect that an attacker is using lateral movement via WMI. Which command in Splunk would best assist in identifying anomalous process creation events associated with WMI (wmiprvse.exe) spawning shells?
Medium126Which component in the Splunk ES architecture is responsible for mapping disparate log sources to a unified schema?
Easy127Which THREE of the following are recognized components of the NIST Cybersecurity Framework (CSF) Core functions?
Medium128You notice that the risk score for an asset is not decaying. Which configuration controls the risk score lifespan?
Hard129You are analyzing a data model using tstats. You need to identify rare process executions across your environment. Which command structure provides the most performance-optimized result?
Hard130You are troubleshooting a scenario where the 'Risk Notable' is not firing as expected. Which log file should you inspect first to confirm if the Risk Analysis action was successfully triggered?
Hard131A SOC analyst observes an unusual spike in failed login attempts followed by a successful login from a new IP address. Which Splunk Enterprise Security dashboard should the analyst check to confirm if this is a potential brute-force attack?
Easy132When troubleshooting a missing notable event, which search should you run to verify if the correlation search is producing results?
Medium133Which component of the Splunk Enterprise Security architecture is responsible for generating notable events?
Medium134You need to calculate the average time delta between 'login' and 'logout' events for each user. Which command approach is most effective?
Hard135Which TWO actions can be taken on a notable event directly from the Incident Review dashboard?
Hard136If an analyst wants to see all risk events associated with a specific IP address, which search command is most effective?
Medium137You are auditing your environment against the NIST CSF 'Detect' function. Which TWO of the following Splunk ES features provide the necessary visibility?
Hard138You are configuring a new Data Model for use with Splunk Enterprise Security. Which action is required to ensure the data model accelerates correctly for use in notable event generation?
Medium139A malware infection is suspected on a host. You notice traffic on port 445. Which Splunk ES correlation search should be prioritized to investigate lateral movement?
Hard140In the context of Splunk ES, what is an 'Asset'?
Easy141Which TWO of the following are valid methods for enriching notable events in Splunk ES?
Medium142Which of the following is considered 'Reconnaissance' in the Cyber Kill Chain?
Easy143Which TWO methods can be used to suppress notable events?
Hard144Which THREE of the following fields are required for mapping data to the 'Authentication' CIM data model?
Hard145An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk events?
Hard146An analyst needs to correlate an alert with the 'Delivery' phase of the Cyber Kill Chain. Which data source should be most prioritized for this specific stage?
Easy147Which TWO areas of the Splunk ES environment are used to manage risk-based alerting configurations?
Easy148You are integrating Splunk with the CIS Benchmarks. Which TWO of the following configurations are necessary to report on 'Secure Configuration' of endpoints?
Hard149When investigating a case, where should an analyst document their findings to ensure they are available to other team members?
Medium150You want to suppress a specific correlation search alert for a legitimate vulnerability scan. What is the most precise way to achieve this without disabling the search?
Hard151You need to modify the default 'Risk Score' logic for a specific asset. Where should this customization occur?
Hard152Which THREE commands can be used to handle or create statistical summaries?
Hard153A security analyst needs to adjust the weight of a specific risk rule. Where should this configuration be modified?
Medium154Which command is used to rename a field in the results table for better readability?
Easy155When configuring a correlation search, what does the 'Notable Event' field 'Urgency' determine?
Medium156You are troubleshooting why a specific Correlation Search is not appearing in the Incident Review dashboard despite the search returning results. What is the most likely cause?
Hard157Which phase of the Cyber Kill Chain is most effectively mitigated by implementing strict egress filtering on your firewall?
Easy158Which command allows you to limit the number of fields displayed in your final results table?
Easy159A correlation search is failing to generate notable events due to a time-zone mismatch in the source data. What is the best way to handle this in Splunk?
Hard160You are configuring a new Risk-Based Alerting (RBA) workflow. Which component is responsible for transforming raw logs into risk notables within the Splunk Enterprise Security app?
Easy161You need to append the contents of a lookup file 'threat_intel.csv' to your search results based on the field 'src_ip'. Which command is correct?
Medium162Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?
Easy163What does the 'OR' operator do in a search?
Easy164Which TWO of the following are true regarding the configuration of notable events in Splunk ES?
Medium165Which command would you use to filter out events where the 'status' field is 200?
Medium166Which THREE attributes are commonly used to filter notable events in the Incident Review dashboard?
Medium167You suspect an attacker is using 'living-off-the-land' (LotL) techniques. Which Sysmon event should you analyze to see command-line arguments of suspicious utilities?
Medium168When hunting for lateral movement, which THREE data sources are most valuable for correlation?
Hard169Which TWO commands are helpful for identifying specific patterns in data?
Medium170Where should you perform the initial configuration of the Splunk Common Information Model (CIM) to ensure data is correctly normalized for Enterprise Security?
Easy171Which THREE of the following are benefits of using Risk-Based Alerting (RBA) in Splunk ES?
Hard172An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?
Hard173Which THREE commands are used to manipulate multi-value fields?
Hard174Which THREE of the following are valid ways to filter events based on time?
Hard175You are tasked with reporting on 'Lateral Movement' (MITRE ATT&CK) using Splunk ES. Which Data Model must be populated and enabled for this report to function correctly?
Medium176Which dashboard provides a summary of all assets categorized by their criticality within the organization?
Medium177Your organization is adopting the CIS Controls v8. You are using Splunk to track 'Inventory and Control of Enterprise Assets'. Which Data Model is essential for this visibility?
Medium178When using 'stats', how can you include the values of a field as columns in your output?
Hard179Which TWO of the following are key components of the Splunk ES Threat Intelligence framework?
Easy180You are configuring CIS Benchmarks in Splunk for your Linux environment. Which tool/app is the standard for ingesting and reporting these compliance checks?
Medium181An analyst identifies a command-and-control (C2) beaconing pattern. Which search command would be best used to identify the frequency of connections to a specific domain?
Medium182Which command is used to append results from one search to another?
Easy183When configuring the 'Risk Analysis' adaptive response, what does the 'risk_score' parameter represent?
Hard184What is the primary function of the 'Risk Notable' correlation search in Splunk ES?
Medium185When dealing with multi-value fields, which command allows you to break them into individual events?
Hard186What is the purpose of the 'Incident Review' dashboard in Splunk ES?
Easy187Which TWO types of events are typically categorized as 'Notable Events'?
Medium188Which command is used to remove duplicate events based on a field?
Medium189Which THREE actions are necessary to successfully onboard a new data source into Splunk Enterprise Security?
Medium190In the context of the NIST CSF 'Identify' function, which Splunk functionality is most appropriate for maintaining a current list of authorized software?
Hard191Which TWO of the following are primary indicators of a phishing attack that you should look for in email logs?
Easy192An attacker has modified the registry to ensure persistence. Which Splunk ES data model tracks Windows registry changes?
Hard193Which TWO types of data are commonly enriched by the Asset and Identity framework?
Easy194Which TWO Splunk features are best for automating the execution of recurring threat hunts?
Medium195Which TWO commands are commonly used to remove or limit the results returned by a search?
Medium196Which TWO of these commands are used for data visualization prep?
Medium197When configuring a risk-based correlation search, what is the primary purpose of the 'Risk Analysis' adaptive response action?
Medium198You need to ensure that your Splunk ES environment is properly ingesting threat intelligence data. Where can you confirm that threat sources are active?
Hard199You are auditing logs and find that a user has modified an audit policy using 'auditpol.exe'. Which Splunk CIM data model should contain this information?
Hard200A security analyst needs to reduce the noise generated by a specific correlation search that triggers too frequently for authorized internal vulnerability scanners. What is the most efficient way to handle this in Splunk ES?
Medium201Which THREE of the following data models are critical for monitoring lateral movement within a network?
Medium202You need to correlate a VPN login with a subsequent file access on an internal server. Which Splunk ES feature helps you link these disparate events?
Medium203Which of the following best describes the goal of the 'Exploitation' phase in the Cyber Kill Chain?
EasyOther domains
All SPLK-5001 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the SPLK-5001 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 203 troubleshooting questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.