Skip to content

Certified Cybersecurity Defense Analyst Practice Questions

Prepare for SPLK-5001 with more than an answer.

259 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$130 USD
Level
Intermediate
Valid for
3 years
Domains covered on the exam 6
  1. The Cyber Landscape, Frameworks, and Standards10%
  2. Threat and Attack Types, Motivations, and Tactics20%
  3. Defenses, Data Sources, and SIEM Best Practices20%
  4. Investigation, Event Handling, Correlation, and Risk20%
  5. Using Search Processing Language (SPL)20%
  6. Threat Hunting and Remediation10%
  1. 1

    Select TWO primary benefits of populating and maintaining the Asset and Identity framework in Splunk Enterprise Security. (Select TWO)

    Show answer details

    Correct answer: B, D

    Knowing if a server is a critical production database or a test VM, or if a user is a domain administrator or an intern, is crucial for prioritizing investigations. The Asset and Identity framework provides this essential context.

    The framework allows Splunk to map transient identifiers like IP addresses to persistent assets (e.g., 'WebServer01') and identities (e.g., 'jsmith'). This allows RBA to build a risk profile for the actual entity, not just a temporary network address.

  2. 2

    A threat actor compromises a trusted software vendor's update server and injects malicious code into a legitimate software patch. When the vendor's customers download and install the update, their systems become infected. This type of attack is known as a:

    Show answer details

    Correct answer: B

    A supply chain attack targets a less-secure element in an organization's supply chain, such as a third-party software vendor or partner. By compromising the vendor, the attacker can distribute malware to all of that vendor's customers, as described in the scenario.

  3. 3

    A defense analyst is working in an organization that has adopted a zero trust security model. What is the core principle of this model that should guide the analyst's investigations?

    Show answer details

    Correct answer: B

    The core principle of a zero trust model is to eliminate the concept of a trusted internal network. It operates on the maxim 'never trust, always verify.' Every access request, regardless of its origin, must be authenticated, authorized, and encrypted before being granted. This includes enforcing the principle of least privilege to limit potential damage.

  4. 4

    A SOC wants to assess which of their ingested data sources provide coverage for specific MITRE ATT&CK techniques. The goal is to identify gaps in their visibility and prioritize future data onboarding efforts. Which Splunk tool is specifically designed for this purpose?

    Show answer details

    Correct answer: C

    Splunk Security Essentials (SSE) is a free app that helps organizations understand their security posture. A key feature is the Data Source Check, which maps existing data sources to security use cases and frameworks like MITRE ATT&CK, visually highlighting coverage and identifying gaps.

  5. 5

    A junior analyst is reviewing the Splunk Enterprise Security data flow. They want to understand how unstructured data from various sources is normalized into a common format that high-level security content can use. Which component serves as the bridge between raw data and the accelerated Data Models?

    graph TD A[Raw Data] --> B(Sourcetype & Field Extraction) B --> C{Common Information Model (CIM)} C --> D[Data Models] D --> E((Accelerated Data)) E --> F[ES Dashboards & Correlation Searches]

    Show answer details

    Correct answer: B

    As shown in the diagram, the Common Information Model (CIM) is the essential layer that normalizes data from disparate sources. It provides a standardized set of fields and event categories. Data must be made CIM-compliant before it can be correctly processed by the Data Models, which are then accelerated for high-performance searching by ES content.

  6. 6

    A junior analyst is reviewing the Asset and Identity framework in Splunk ES. They ask why it is critical to keep the asset and identity lookups populated and up-to-date. What are the primary benefits of maintaining this data? (Select TWO)

    Show answer details

    Correct answer: B, C

    Populated asset and identity lists allow ES to enrich raw events with business context, such as which assets are critical servers or which users are executives. This helps analysts quickly determine the potential impact of an alert.

    RBA relies on tracking risk over time for a given entity (risk object). The Asset and Identity framework resolves different identifiers (IP, hostname, MAC, user ID) to a single, consistent asset or identity, allowing risk scores to be aggregated correctly.

  7. 7

    A new data source from a custom application is being onboarded. The logs are not CIM compliant. To use this data effectively in Splunk Enterprise Security, a security engineer must normalize the fields to the CIM. The custom log contains a field named source_ip. What is the corresponding destination field in the CIM 'Network Traffic' data model?

    Show answer details

    Correct answer: C

    The Common Information Model (CIM) uses standardized field names to allow correlation across different data sources. For the Network Traffic data model, the standard field for a source IP address is src. The destination IP address is dest.

  8. 8

    True or False: The primary purpose of Splunk Security Essentials (SSE) is to replace Splunk Enterprise Security as a full-featured SIEM.

    Show answer details

    Correct answer: B

    Splunk Security Essentials (SSE) is a free app that acts as a guide and showcase for security use cases. Its purpose is to help users identify necessary data sources, understand potential detections, and deploy security content. It is a companion and on-ramp to Splunk Enterprise Security (ES), not a replacement for ES, which is the full-featured, premium SIEM solution.

  9. 9

    Which of the following describes the difference between a bot and a botnet?

    Show answer details

    Correct answer: C

    This is the correct definition. A 'bot' (short for robot) is an individual computer that has been infected with malware allowing it to be controlled remotely. A 'botnet' is the entire collection or network of these compromised bots, which can be commanded simultaneously by an attacker (the 'bot herder') to perform large-scale malicious activities like DDoS attacks or spam campaigns.

  10. 10

    What are the primary goals of implementing a zero trust security model? (Select ALL that apply)

    Show answer details

    Correct answer: B, C, D

    This is a core principle of zero trust. It assumes that threats can exist both inside and outside the traditional network perimeter, so no user or device is trusted by default.

    The mantra of zero trust is 'never trust, always verify'. Every access request must be authenticated and authorized, regardless of its location on the network.

    Zero trust architectures grant users and devices only the minimum level of access necessary to perform their specific tasks, reducing the potential impact of a compromised account or device.

Create an account to continue.