Splunk SPLK-5001 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-5001
- Exam Name: Splunk Certified Cybersecurity Defense Analyst
- Certification Provider: Splunk
- Latest update: Oct 06,2026
An analyst would like to test how certain Splunk SPL commands work against a small set of dat
a.
What command should start the search pipeline if they wanted to create their own data instead of utilizing data contained within Splunk?
- A . makeresults
- B . rename
- C . eval
- D . stats
An analyst would like to test how certain Splunk SPL commands work against a small set of dat
a.
What command should start the search pipeline if they wanted to create their own data instead of utilizing data contained within Splunk?
- A . makeresults
- B . rename
- C . eval
- D . stats
In which phase of the Continuous Monitoring cycle are suggestions and improvements typically made?
- A . Define and Predict
- B . Establish and Architect
- C . Analyze and Report
- D . Implement and Collect
Which of the following is not considered an Indicator of Compromise (IOC)?
- A . A specific domain that is utilized for phishing.
- B . A specific IP address used in a cyberattack.
- C . A specific file hash of a malicious executable.
- D . A specific password for a compromised account.
An analyst is examining the logs for a web application’s login form. They see thousands of failed logon attempts using various usernames and passwords. Internet research indicates that these credentials may have been compiled by combining account information from several recent data breaches.
Which type of attack would this be an example of?
- A . Credential sniffing
- B . Password cracking
- C . Password spraying
- D . Credential stuffing
Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain® to be mapped to Correlation Search results?
- A . Annotations
- B . Playbooks
- C . Comments
- D . Enrichments
Which of the following is a tactic used by attackers, rather than a technique?
- A . Gathering information about a target.
- B . Establishing persistence with a scheduled task.
- C . Using a phishing email to gain initial access.
- D . Escalating privileges via UAC bypass.
An analyst is investigating a network alert for suspected lateral movement from one Windows host to another Windows host.
According to Splunk CIM documentation, the IP address of the host from which the attacker is moving would be in which field?
- A . host
- B . dest
- C . src_nt_host
- D . src_ip
186.119.200 – – [28/Jul/2023:12:04:13 -0300] "GET /login/ HTTP/1.0" 200 3733 What kind of attack is occurring?
- A . Denial of Service Attack
- B . Distributed Denial of Service Attack
- C . Cross-Site Scripting Attack
- D . Database Injection Attack
Use EternalBlue to exploit a remote SMB server In which order are they listed below?
- A . Tactic, Technique, Procedure
- B . Procedure, Technique, Tactic
- C . Technique, Tactic, Procedure
- D . Tactic, Procedure, Technique