SPLK-5001 Exam Questions
121 real SPLK-5001 exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #101Introduction to Cybersecurity and Splunk
Which of the following is not considered a type of default metadata in Splunk?
Splunk metadatadefault fieldssourcetypehost - Question #102Incident Investigation and Response
Which dashboard in Enterprise Security would an analyst use to generate a report on users who are currently on a watchlist?
Enterprise Security dashboardsIdentity Trackerwatchlistuser monitoring - Question #103Introduction to Cybersecurity and Splunk
This technique is used by attackers to hide the presence of components like programs, files, and network connections by hooking into the OS and intercepting system API calls. It ca...
rootkitmalware techniquesOS hookingkernel-level attack - Question #104Incident Investigation and Response
What phase of the continuous monitoring cycle might include the creation of an after action report highlighting the findings and recommendations for the next phase of the cycle?
continuous monitoring cycleafter action reportrespond and reviewincident lifecycle - Question #105Threat Detection and Alerting
Outlier detection is an analysis method that groups together data points into high density clusters. Data points that fall outside of these high density clusters are considered to...
outlier detectionanomaly detectionclusteringbehavioral analysis - Question #106Incident Investigation and Response
The Security Operations team would like to track improvements after customizing dashboards to help analysts triage security alerts more efficiently. Which metric would they use?
MTTDSOC metricsmean time to detecttriage efficiency - Question #107Security Data Onboarding and Normalization
Which of the following data sources would be most useful to determine if a user visited a recently identified malicious website?
web proxy logsdata sourcesmalicious website detectionnetwork traffic - Question #108Security Data Onboarding and Normalization
Which argument would an analyst use to search only accelerated data contained in the Network Traffic Data Model with the tstats command?
tstatsdata model accelerationsummariesonlyNetwork Traffic Data Model - Question #109Introduction to Cybersecurity and Splunk
Which tool can a SOC analyst use to explore existing SPL searches that might be helpful during investigations?
Splunk Security EssentialsSOC toolsSPL search libraryinvestigation tools - Question #110Incident Investigation and Response
While investigating a finding in Splunk, an analyst manually searches for threat intelligence matches and adds them to a list if they come back as malicious. Then, they send a requ...
SOAR playbookautomationthreat intelligencehost containment - Question #111Threat Detection and Alerting
Which Splunk ES feature detects complex behavior over a "period of time" instead of "point in time" alerting?
Risk Based AlertingRBAEnterprise Securitybehavioral detection - Question #112Security Data Onboarding and Normalization
Which of the following is a reason to use Data Model Acceleration in Splunk?
data model accelerationsearch performanceCIMdata models - Question #113Threat Detection and Alerting
Splunk detections can be mapped to their appropriate MITRE ATT&CK® Techniques using which feature?
MITRE ATT&CKannotationsdetection mappingEnterprise Security - Question #114Threat Detection and Alerting
A threat hunter is analyzing incoming emails during the past 30 days, looking for spam or phishing campaigns targeting many users. This involves finding large numbers of similar, b...
clusteringmachine learningphishing detectionthreat hunting - Question #115Introduction to Cybersecurity and Splunk
A network security tool that continuously monitors a network for malicious activity and takes action to block it is known as which of the following?
IPSintrusion prevention systemnetwork security toolsactive blocking - Question #116Introduction to Cybersecurity and Splunk
Which set of behaviors describes an Advanced Persistent Threat (APT) group focused on compromising accounts of senior executives?Phishing with ransomware.
APTspearphishingtargeted attackthreat actors - Question #117Compliance and Reporting
Which of the following compliance frameworks was specifically created to measure the level of cybersecurity maturity within an organization?
CMMCcompliance frameworkscybersecurity maturityregulatory compliance - Question #118Incident Investigation and Response
As an analyst, tracking unique users is a common occurrence. The Security Operations Center (SOC) manager requested a search with results in a table format to track the cumulative...
SPL statsdistinct valuesdata analysisuser tracking - Question #119Security Data Onboarding and Normalization
Which of the following SPL searches is likely to return results the fastest?
SPL optimizationsearch performanceindex filteringsourcetype filtering - Question #120Incident Investigation and Response
Splunk SOAR uses what feature to automate security workflows so that analysts can spend more time performing analysis and investigation?
SOARplaybookssecurity automationworkflow orchestration - Question #121Security Data Onboarding and Normalization
An analyst learns that several types of data are being ingested into Splunk and Enterprise Security, and wants to use the metadata SPL command to list them in a search. Which of th...
SPL metadata commandsourcetypesdata ingestionSplunk search