Courseiva

SPLK-5001 · domain

troubleshooting

Practise Splunk Certified Cybersecurity Defense Analyst (SPLK-5001) (SPLK-5001) troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

203 questions49 easy83 medium71 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (203)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are key components of a successful incident investigation workflow in Splunk ES?

Easy
2

Which THREE tasks are performed within the 'CIM Setup' interface?

Medium
3

What is the purpose of the 'head' command?

Easy
4

An attacker is using a technique that involves 'living off the land' by utilizing legitimate system tools. Which data model is most effective to monitor these tools?

Hard
5

You are configuring the Splunk Security Essentials (SSE) app to align with the NIST CSF framework. You want to prioritize your detection development based on the most critical gaps. Which action should you take?

Hard
6

You need to ensure that only authorized users can view certain sensitive notable events. How do you implement this in Splunk ES?

Medium
7

When drafting a threat hunting playbook, which of the following sections is most critical for ensuring the hunt is repeatable and auditable by other analysts?

Easy
8

A security engineer is configuring a new correlation search that needs to correlate data across two different indexes. Which Splunk ES feature allows for efficient correlation across large datasets?

Hard
9

Which TWO of the following commands are used for data transformation or enrichment?

Medium
10

Which phase of the proactive threat hunting methodology involves identifying the specific threat actor or technique to be investigated?

Easy
11

A security analyst notices an alert from the 'MITRE ATT&CK - Initial Access' tactic. Which data source should be primary for investigating this alert?

Medium
12

Which character acts as a wildcard in a search string?

Easy
13

A user reports that a specific dashboard panel is timing out. After checking the search job, you notice it is scanning too much data. Which configuration should you adjust?

Hard
14

You are investigating a potential beaconing pattern. You have identified a suspect destination IP. Which SPL command sequence is most appropriate to calculate the frequency of connections to this IP to validate the beaconing hypothesis?

Hard
15

When configuring an 'Adaptive Response' action, what does the 'Notable' action type do?

Hard
16

Which Splunk Enterprise Security feature allows you to manage the lifecycle of a notable event?

Easy
17

An analyst wants to investigate a suspicious email attachment. Which Splunk ES notable event field is most effective for pivoting to the 'File' domain investigation dashboard?

Easy
18

You are using a subsearch to find 'dest_ip' values that appeared in a 'failed_login' search. What is a common limitation of subsearches that you must consider?

Hard
19

Which THREE pieces of information are commonly found in a Splunk ES Case?

Easy
20

Which TWO factors influence an object's final risk score in Splunk ES?

Hard
21

Which TWO commands provide information about the fields present in the events?

Medium
22

Which dashboard in Splunk ES provides a high-level view of threats and vulnerabilities mapped to the MITRE ATT&CK framework?

Medium
23

An analyst needs to manually add an event to an existing case in Splunk ES. What is the correct procedure?

Medium
24

Which THREE dashboard categories in Splunk ES are most useful for risk-based investigation?

Medium
25

Which THREE components are required for an Adaptive Response action to function?

Medium
26

You are creating a custom Adaptive Response action. The action requires a Python script. Where must this script be placed for the Splunk instance to execute it?

Hard
27

You are creating a custom correlation search that triggers a notable event. How do you ensure the notable event maintains the correct 'owner' assignment when the search triggers for multiple distinct users?

Hard
28

When designing a threat hunting playbook, which TWO components must be included to ensure the hunt is actionable?

Medium
29

An attacker has cleared the Windows Event Logs to hide their tracks. You are hunting for this activity. Which Event ID in the System log indicates that the log service was stopped or cleared?

Hard
30

You are investigating a user who has triggered multiple high-risk alerts. Where in Splunk ES can you view the historical risk score progression for this specific user?

Hard
31

Which THREE actions are part of the 'Incident Review' investigation workflow?

Easy
32

Which THREE of the following data sources are most valuable for detecting an insider threat?

Medium
33

What is the effect of changing the 'Retention Period' in the Enterprise Security app settings?

Medium
34

You are hunting for anomalous PowerShell activity. Which THREE indicators or behaviors should you look for in your Splunk data?

Hard
35

Which command is used to calculate the 'count' of events and concurrently keep the original 'raw' text?

Hard
36

When reviewing an incident, how can an analyst verify if the notable event was generated by a specific correlation search?

Medium
37

You have a field 'raw_data' containing JSON. How do you extract fields from it within your SPL search?

Hard
38

What is the purpose of the 'map' command in complex searches?

Hard
39

What is the purpose of the 'Investigation Workbench' in Splunk ES?

Easy
40

When investigating a risk notable, which dashboard in Splunk ES provides a visual representation of the risk contributors for a specific user?

Easy
41

What is the purpose of the 'Assets and Identities' framework in Splunk ES?

Medium
42

Which THREE of the following are necessary prerequisites for ensuring a new data source is correctly utilized by the ES 'Access' data model?

Hard
43

Which THREE of the following represent the categories of threat intelligence that can be managed within the Splunk Enterprise Security 'Threat Intelligence' framework?

Medium
44

A user account is exhibiting signs of being compromised. Where can you find the user's recent login history in Splunk ES?

Easy
45

Which TWO actions should be taken if a correlation search is consuming too many system resources?

Hard
46

You are configuring Splunk Enterprise Security to monitor for MITRE ATT&CK 'Persistence' techniques. Which TWO data sources provide the highest fidelity logs for detecting registry-based persistence?

Hard
47

In the Incident Review dashboard, what does 'Status' represent?

Easy
48

Which command is used to visualize data in a time-series chart?

Easy
49

You want to find the total count of events per hour over the last week. Which command sequence is most efficient?

Medium
50

When using the 'Risk Analysis' framework in Splunk ES, what is the primary benefit of assigning a 'Risk Object'?

Medium
51

A customer wants to exclude certain low-fidelity risk events from their Risk Notable correlation search. Where is the best place to define these exclusions?

Medium
52

You need to verify if an external IP address is a known malicious TOR exit node. Which Splunk ES feature should you use?

Medium
53

What is the primary function of the 'Incident Review' dashboard in Splunk ES?

Easy
54

When utilizing the Splunk Common Information Model (CIM), which field name is standard for identifying the destination IP address across different data sources?

Hard
55

You want to dynamically update a lookup table with new indicators of compromise (IOCs) found during your search. Which command is used for this?

Hard
56

You notice a system process attempting to connect to a suspicious external domain. Which CIM data model would contain this network connection information?

Easy
57

What is the result of using 'bin _time span=1d'?

Medium
58

Which Splunk ES component would you use to define a new correlation rule based on a custom blacklist of domains?

Easy
59

Which TWO actions should be performed during the 'Data Preparation' phase of a threat hunt to ensure accurate results?

Medium
60

Which TWO metrics are tracked in the 'Incident Review' dashboard's 'Notable Event' list?

Medium
61

An attacker is using a technique to hide in plain sight by renaming a common system process. Which data model is most suitable for comparing process names against known good paths?

Hard
62

Which THREE features are provided by the Splunk ES Incident Review dashboard?

Medium
63

Which field is mandatory for an event to be correctly categorized by the Common Information Model (CIM) 'Network Traffic' data model?

Medium
64

An attacker is attempting to use a 'Pass-the-Hash' technique. Which authentication log event code in Windows (Event ID 4624) should you look for to detect this?

Medium
65

Which THREE things are required for Splunk Enterprise Security to provide meaningful security insights?

Easy
66

If an analyst needs to modify the default retention for the 'risk' index, where should they make this change?

Hard
67

Where do you go in Splunk ES to adjust the sensitivity (risk score) of a specific correlation search?

Easy
68

Which THREE of the following components are part of the 'Endpoint' data model?

Medium
69

You are investigating a potential insider threat involving unauthorized data exfiltration. Which Splunk ES feature allows you to correlate multiple events occurring over a long duration to a single entity?

Medium
70

You are using 'lookup' to add user info. What happens if the common field doesn't exist in the lookup file?

Medium
71

Which TWO methods can be used to suppress unwanted notable events?

Medium
72

Which TWO factors are critical for effective Asset and Identity enrichment?

Medium
73

You are configuring a 'Notable Event' to use a specific 'Drilldown' link. What syntax is used to pass fields from the event into the URL?

Hard
74

When aligning Splunk Enterprise Security with the NIST CSF 'Recover' function, which feature is most applicable for documenting the incident response process?

Hard
75

Which TWO factors directly impact the urgency of a notable event in Splunk ES?

Hard
76

Which TWO commands require a grouping field to function correctly?

Medium
77

Which THREE of the following are common indicators that a host has been infected with malware?

Hard
78

In a threat hunting workflow, what is the primary purpose of a 'Lookback' period?

Easy
79

Which component in Splunk ES is used to manage the lifecycle of an incident, including status updates and assignments?

Easy
80

You are hunting for evidence of credential dumping. You have access to Sysmon logs. Which EventCode should be the primary focus for detecting memory access to lsass.exe?

Medium
81

When onboarding a new firewall source, you notice that the data is not populating the 'Network Traffic' data model. What is the most efficient first step to troubleshoot the CIM mapping?

Medium
82

How can you ensure that a search field is only treated as a number for calculation purposes?

Hard
83

You want to visualize the geographic origin of incoming connection attempts to identify potentially malicious traffic. Which dashboard is most appropriate?

Medium
84

Which THREE of the following are valid uses of the 'eval' command?

Hard
85

You are mapping incoming alerts to the MITRE ATT&CK framework within the Splunk Enterprise Security (ES) Incident Review dashboard. Which attribute mapping ensures that your TTP-based notable events correctly reflect the adversary behavior?

Medium
86

Which data model does the Risk Analysis adaptive response action typically rely upon to enrich events?

Medium
87

You want to calculate the standard deviation of 'response_time' per 'server'. Which command is correct?

Medium
88

Which THREE diagnostic tools or logs are useful for troubleshooting a malfunctioning correlation search?

Hard
89

Which THREE settings can be configured within the 'Risk Analysis' adaptive response action?

Hard
90

Which Splunk ES dashboard allows you to view and manage active threat intelligence feeds?

Easy
91

You are troubleshooting an 'Adaptive Response' action that is failing to execute on a remote device. What should you check first?

Medium
92

Which TWO of the following are common types of social engineering?

Medium
93

An attacker is using PowerShell to obfuscate their activities. Which data model is most appropriate for searching for encoded PowerShell commands?

Medium
94

You are performing a search and want to ensure the subsearch runs against a specific time range relative to the main search. Which command/option achieves this?

Medium
95

Which THREE elements are essential for a well-defined risk-based alert?

Hard
96

You want to use the 'eval' command to create a new field 'is_critical' that is 'yes' if 'severity' is 'high' or 'critical', and 'no' otherwise. Which syntax is correct?

Medium
97

A correlation search is failing to generate risk events. You check the 'Search Activity' and see that the search is running but returning 0 results. What is the most likely cause?

Hard
98

Which THREE of the following are common phases defined in the Cyber Kill Chain model?

Medium
99

When a notable event is generated, where does the 'Risk Score' value originate?

Medium
100

Which TWO of the following are ways to verify if a file hash is truly malicious within Splunk ES?

Hard
101

During an investigation, you need to group related notables into a single investigation container. Which feature should you use?

Medium
102

Which Splunk ES dashboard allows an analyst to see a summary of all active notable events currently requiring investigation?

Easy
103

A phishing campaign is targeting your organization. Which Splunk ES module is best suited to track the delivery of the malicious email URLs?

Easy
104

Which TWO of the following are examples of reconnaissance techniques used by attackers?

Easy
105

You need to ensure that the 'Threat Intelligence' framework periodically updates. Where do you configure the update interval?

Hard
106

Which THREE techniques can be used in Splunk to reduce the noise of false positives during a threat hunt?

Hard
107

You are conducting a hunt for unauthorized remote access tools. Which Splunk command is most effective for identifying processes that are running from unusual directories (e.g., AppData, Temp)?

Medium
108

Which THREE of the following are valid search operators?

Hard
109

Which TWO ways can you enrich events with threat intelligence in Splunk ES?

Hard
110

You are onboarding a new Windows Event Log source using the Splunk Universal Forwarder. To ensure the data conforms to the Splunk Common Information Model (CIM) for the Authentication data model, where should you primarily configure the sourcetype?

Medium
111

Which search command is used to join threat intelligence data with your local search results?

Easy
112

Which TWO of the following are valid methods to mitigate an insider threat within Splunk ES?

Medium
113

Which THREE of the following represent valid ways to use the 'lookup' command?

Hard
114

Which Splunk feature allows an analyst to save a specific search query, parameterize it with variables, and reuse it across different time ranges and entities?

Easy
115

When calculating a risk score using the 'sum' aggregation method, what happens if multiple risk events for the same object occur within the same time window?

Hard
116

You notice a high volume of traffic from an internal workstation to a non-standard port on an external server. Which search helps identify the frequency of this connection?

Hard
117

You are investigating a potential web-based attack. Which data model contains information regarding HTTP user-agents and request methods?

Medium
118

When using the Splunk Enterprise Security 'Threat Intelligence' framework, which file type is used to import custom STIX/TAXII threat feeds to align with the MITRE ATT&CK framework?

Hard
119

You are investigating a potential data exfiltration event. You have a lookup file called 'authorized_servers.csv' containing a field 'ip_address'. You want to find all connections to IPs not in this list. Which command fulfills this?

Medium
120

You are investigating a suspicious PowerShell script. You suspect the script is using Base64 encoding. Which SPL function can you use to decode the string within Splunk?

Medium
121

What is the primary function of the 'Notable Event Suppression' feature?

Easy
122

You are reviewing a Splunk Enterprise Security alert mapped to the MITRE ATT&CK technique 'T1059.001 (PowerShell)'. Which search command would best identify the use of obfuscated PowerShell commands?

Hard
123

What is the benefit of using the Asset and Identity framework in Splunk ES investigations?

Easy
124

In Splunk ES, where can you manage the 'Risk Threshold' for triggering a Notable Event based on aggregate risk scores?

Easy
125

You are performing a hypothesis-driven hunt and suspect that an attacker is using lateral movement via WMI. Which command in Splunk would best assist in identifying anomalous process creation events associated with WMI (wmiprvse.exe) spawning shells?

Medium
126

Which component in the Splunk ES architecture is responsible for mapping disparate log sources to a unified schema?

Easy
127

Which THREE of the following are recognized components of the NIST Cybersecurity Framework (CSF) Core functions?

Medium
128

You notice that the risk score for an asset is not decaying. Which configuration controls the risk score lifespan?

Hard
129

You are analyzing a data model using tstats. You need to identify rare process executions across your environment. Which command structure provides the most performance-optimized result?

Hard
130

You are troubleshooting a scenario where the 'Risk Notable' is not firing as expected. Which log file should you inspect first to confirm if the Risk Analysis action was successfully triggered?

Hard
131

A SOC analyst observes an unusual spike in failed login attempts followed by a successful login from a new IP address. Which Splunk Enterprise Security dashboard should the analyst check to confirm if this is a potential brute-force attack?

Easy
132

When troubleshooting a missing notable event, which search should you run to verify if the correlation search is producing results?

Medium
133

Which component of the Splunk Enterprise Security architecture is responsible for generating notable events?

Medium
134

You need to calculate the average time delta between 'login' and 'logout' events for each user. Which command approach is most effective?

Hard
135

Which TWO actions can be taken on a notable event directly from the Incident Review dashboard?

Hard
136

If an analyst wants to see all risk events associated with a specific IP address, which search command is most effective?

Medium
137

You are auditing your environment against the NIST CSF 'Detect' function. Which TWO of the following Splunk ES features provide the necessary visibility?

Hard
138

You are configuring a new Data Model for use with Splunk Enterprise Security. Which action is required to ensure the data model accelerates correctly for use in notable event generation?

Medium
139

A malware infection is suspected on a host. You notice traffic on port 445. Which Splunk ES correlation search should be prioritized to investigate lateral movement?

Hard
140

In the context of Splunk ES, what is an 'Asset'?

Easy
141

Which TWO of the following are valid methods for enriching notable events in Splunk ES?

Medium
142

Which of the following is considered 'Reconnaissance' in the Cyber Kill Chain?

Easy
143

Which TWO methods can be used to suppress notable events?

Hard
144

Which THREE of the following fields are required for mapping data to the 'Authentication' CIM data model?

Hard
145

An analyst is investigating an incident where a user's risk score spiked significantly. Which investigative tool allows the analyst to see the timeline of all contributing risk events?

Hard
146

An analyst needs to correlate an alert with the 'Delivery' phase of the Cyber Kill Chain. Which data source should be most prioritized for this specific stage?

Easy
147

Which TWO areas of the Splunk ES environment are used to manage risk-based alerting configurations?

Easy
148

You are integrating Splunk with the CIS Benchmarks. Which TWO of the following configurations are necessary to report on 'Secure Configuration' of endpoints?

Hard
149

When investigating a case, where should an analyst document their findings to ensure they are available to other team members?

Medium
150

You want to suppress a specific correlation search alert for a legitimate vulnerability scan. What is the most precise way to achieve this without disabling the search?

Hard
151

You need to modify the default 'Risk Score' logic for a specific asset. Where should this customization occur?

Hard
152

Which THREE commands can be used to handle or create statistical summaries?

Hard
153

A security analyst needs to adjust the weight of a specific risk rule. Where should this configuration be modified?

Medium
154

Which command is used to rename a field in the results table for better readability?

Easy
155

When configuring a correlation search, what does the 'Notable Event' field 'Urgency' determine?

Medium
156

You are troubleshooting why a specific Correlation Search is not appearing in the Incident Review dashboard despite the search returning results. What is the most likely cause?

Hard
157

Which phase of the Cyber Kill Chain is most effectively mitigated by implementing strict egress filtering on your firewall?

Easy
158

Which command allows you to limit the number of fields displayed in your final results table?

Easy
159

A correlation search is failing to generate notable events due to a time-zone mismatch in the source data. What is the best way to handle this in Splunk?

Hard
160

You are configuring a new Risk-Based Alerting (RBA) workflow. Which component is responsible for transforming raw logs into risk notables within the Splunk Enterprise Security app?

Easy
161

You need to append the contents of a lookup file 'threat_intel.csv' to your search results based on the field 'src_ip'. Which command is correct?

Medium
162

Which of the following is a primary benefit of Risk-Based Alerting (RBA) over traditional alerting?

Easy
163

What does the 'OR' operator do in a search?

Easy
164

Which TWO of the following are true regarding the configuration of notable events in Splunk ES?

Medium
165

Which command would you use to filter out events where the 'status' field is 200?

Medium
166

Which THREE attributes are commonly used to filter notable events in the Incident Review dashboard?

Medium
167

You suspect an attacker is using 'living-off-the-land' (LotL) techniques. Which Sysmon event should you analyze to see command-line arguments of suspicious utilities?

Medium
168

When hunting for lateral movement, which THREE data sources are most valuable for correlation?

Hard
169

Which TWO commands are helpful for identifying specific patterns in data?

Medium
170

Where should you perform the initial configuration of the Splunk Common Information Model (CIM) to ensure data is correctly normalized for Enterprise Security?

Easy
171

Which THREE of the following are benefits of using Risk-Based Alerting (RBA) in Splunk ES?

Hard
172

An attacker has cleared the Windows Security Event log to hide their tracks. Which data model can detect this action?

Hard
173

Which THREE commands are used to manipulate multi-value fields?

Hard
174

Which THREE of the following are valid ways to filter events based on time?

Hard
175

You are tasked with reporting on 'Lateral Movement' (MITRE ATT&CK) using Splunk ES. Which Data Model must be populated and enabled for this report to function correctly?

Medium
176

Which dashboard provides a summary of all assets categorized by their criticality within the organization?

Medium
177

Your organization is adopting the CIS Controls v8. You are using Splunk to track 'Inventory and Control of Enterprise Assets'. Which Data Model is essential for this visibility?

Medium
178

When using 'stats', how can you include the values of a field as columns in your output?

Hard
179

Which TWO of the following are key components of the Splunk ES Threat Intelligence framework?

Easy
180

You are configuring CIS Benchmarks in Splunk for your Linux environment. Which tool/app is the standard for ingesting and reporting these compliance checks?

Medium
181

An analyst identifies a command-and-control (C2) beaconing pattern. Which search command would be best used to identify the frequency of connections to a specific domain?

Medium
182

Which command is used to append results from one search to another?

Easy
183

When configuring the 'Risk Analysis' adaptive response, what does the 'risk_score' parameter represent?

Hard
184

What is the primary function of the 'Risk Notable' correlation search in Splunk ES?

Medium
185

When dealing with multi-value fields, which command allows you to break them into individual events?

Hard
186

What is the purpose of the 'Incident Review' dashboard in Splunk ES?

Easy
187

Which TWO types of events are typically categorized as 'Notable Events'?

Medium
188

Which command is used to remove duplicate events based on a field?

Medium
189

Which THREE actions are necessary to successfully onboard a new data source into Splunk Enterprise Security?

Medium
190

In the context of the NIST CSF 'Identify' function, which Splunk functionality is most appropriate for maintaining a current list of authorized software?

Hard
191

Which TWO of the following are primary indicators of a phishing attack that you should look for in email logs?

Easy
192

An attacker has modified the registry to ensure persistence. Which Splunk ES data model tracks Windows registry changes?

Hard
193

Which TWO types of data are commonly enriched by the Asset and Identity framework?

Easy
194

Which TWO Splunk features are best for automating the execution of recurring threat hunts?

Medium
195

Which TWO commands are commonly used to remove or limit the results returned by a search?

Medium
196

Which TWO of these commands are used for data visualization prep?

Medium
197

When configuring a risk-based correlation search, what is the primary purpose of the 'Risk Analysis' adaptive response action?

Medium
198

You need to ensure that your Splunk ES environment is properly ingesting threat intelligence data. Where can you confirm that threat sources are active?

Hard
199

You are auditing logs and find that a user has modified an audit policy using 'auditpol.exe'. Which Splunk CIM data model should contain this information?

Hard
200

A security analyst needs to reduce the noise generated by a specific correlation search that triggers too frequently for authorized internal vulnerability scanners. What is the most efficient way to handle this in Splunk ES?

Medium
201

Which THREE of the following data models are critical for monitoring lateral movement within a network?

Medium
202

You need to correlate a VPN login with a subsequent file access on an internal server. Which Splunk ES feature helps you link these disparate events?

Medium
203

Which of the following best describes the goal of the 'Exploitation' phase in the Cyber Kill Chain?

Easy

Frequently asked questions

What does the troubleshooting domain cover on the SPLK-5001 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 203 troubleshooting questions in the SPLK-5001 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.