Splunk

SPLK-5001 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 56-question bank.

Provider
Splunk
Question bank
56
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SPLK-5001, a certification listed under Splunk. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Splunk. The certification credential is issued by Splunk, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which Enterprise Security framework provides a mechanism for running preconfigured actions within the Splunk platform or integrating with external applications?

    Choose one answer.

    • Asset and Identity
    • Notable Event
    • Threat Intelligence
    • Adaptive Response
  2. Question 2 · 1

    An analyst would like to visualize threat objects across their environment and chronological risk events for a Risk Object in Incident Review. Where would they find this?

    Choose one answer.

    • Running the Risk Analysis Adaptive Response action within the Notable Event.
    • Via a workflow action for the Risk Investigation dashboard.
    • Via the Risk Analysis dashboard under the Security Intelligence tab in Enterprise Security.
    • Clicking the risk event count to open the Risk Event Timeline.
  3. Question 3 · 1

    What device typically sits at a network perimeter to detect command and control and other potentially suspicious traffic?

    Choose one answer.

    • Host-based firewall
    • Web proxy
    • Endpoint Detection and Response
    • Intrusion Detection System
  4. Question 4 · 1

    Upon investigating a report of a web server becoming unavailable, the security analyst finds that the web server’s access log has the same log entry millions of times: 147.186.119.200 - - [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733 What kind of attack is occurring?

    Choose one answer.

    • Denial of Service Attack
    • Distributed Denial of Service Attack
    • Cross-Site Scripting Attack
    • Database Injection Attack
  5. Question 5 · 1

    According to David Bianco's Pyramid of Pain, which indicator type is least effective when used in continuous monitoring?

    Choose one answer.

    • Domain names
    • TTPs
    • Network/Host artifacts
    • Hash values
  6. Question 6 · 1

    Which of the following is a correct Splunk search that will return results in the most performant way?

    Choose one answer.

    • index=foo host=i-478619733 | stats range(_time) as duration by src_ip | bin duration span=5min | stats count by duration, host
    • | stats range(_time) as duration by src_ip | index=foo host=i-478619733 | bin duration span=5min | stats count by duration, host
    • index=foo host=i-478619733 | transaction src_ip |stats count by host
    • index=foo | transaction src_ip |stats count by host | search host=i-478619733
  7. Question 7 · 1

    There are many resources for assisting with SPL and configuration questions. Which of the following resources feature community-sourced answers?

    Choose one answer.

    • Splunk Answers
    • Splunk Lantern
    • Splunk Guidebook
    • Splunk Documentation
  8. Question 8 · 1

    A successful Continuous Monitoring initiative involves the entire organization. When an analyst discovers the need for more context or additional information, perhaps from additional data sources or altered correlation rules, to what role would this request generally escalate?

    Choose one answer.

    • SOC Manager
    • Security Analyst
    • Security Engineer
    • Security Architect
  9. Question 9 · 1

    Splunk Enterprise Security has numerous frameworks to create correlations, integrate threat intelligence, and provide a workflow for investigations. Which framework raises the threat profile of individuals or assets to allow identification of people or devices that perform an unusual amount of suspicious activities?

    Choose one answer.

    • Threat Intelligence Framework
    • Risk Framework
    • Notable Event Framework
    • Asset and Identity Framework
  10. Question 10 · 1

    Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain® to be mapped to Correlation Search results?

    Choose one answer.

    • Annotations
    • Playbooks
    • Comments
    • Enrichments
  11. Question 11 · 1

    While the top command is utilized to find the most common values contained within a field, a Cyber Defense Analyst hunts for anomalies. Which of the following Splunk commands returns the least common values?

    Choose one answer.

    • least
    • uncommon
    • rare
    • base
  12. Question 12 · 1

    The Lockheed Martin Cyber Kill Chain® breaks an attack lifecycle into several stages. A threat actor modified the registry on a compromised Windows system to ensure that their malware would automatically run at boot time. Into which phase of the Kill Chain would this fall?

    Choose one answer.

    • Act on Objectives
    • Exploitation
    • Delivery
    • Installation
  13. Question 13 · 1

    A Risk Notable Event has been triggered in Splunk Enterprise Security, an analyst investigates the alert, and determines it is a false positive. What metric would be used to define the time between alert creation and close of the event?

    Choose one answer.

    • MTTR (Mean Time to Respond)
    • MTBF (Mean Time Between Failures)
    • MTTA (Mean Time to Acknowledge)
    • MTTD (Mean Time to Detect)
  14. Question 14 · 1

    An analyst needs to create a new field at search time. Which Splunk command will dynamically extract additional fields as part of a Search pipeline?

    Choose one answer.

    • rex
    • fields
    • regex
    • eval
  15. Question 15 · 1

    Which of the following is considered Personal Data under GDPR?

    Choose one answer.

    • The birth date of an unidentified user.
    • An individual’s address including their first and last name.
    • The name of a deceased individual.
    • A company’s registration number.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free