Skip to content

SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Practice Questions

Prepare for SPLK-5002 with more than an answer.

250 questions in the full set20 sample questionsUpdated Jan 31, 2026
Exam fee
$130 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Data Engineering10%
  2. Detection Engineering40%
  3. Building Effective Security Processes and Programs20%
  4. Automation and Efficiency20%
  5. Auditing and Reporting on Security Programs10%
  1. 1

    You are designing a Splunk SOAR playbook. You need to execute Python code to transform a JSON date format into a human-readable string before passing it to a ticketing system.

    Which playbook block type should you use?

    Show answer details

    Correct answer: B

    A Utility block (specifically the 'Custom Code' or 'Format' type in newer visual editors) allows the insertion of Python code to manipulate data passing through the playbook.

  2. 2

    When creating a new Correlation Search in Enterprise Security, which field is MANDATORY to ensure the resulting Notable Event is correctly associated with a specific Risk Object in the Risk Analysis framework?

    Show answer details

    Correct answer: A

    To correctly attribute risk, you must define WHO or WHAT is at risk. This requires both the risk_object (the value, e.g., 'jdoe') and the risk_object_type (the category, e.g., 'user' or 'system'). Without these, the risk cannot be assigned.

  3. 3

    A SOC Manager wants to ensure that all detections moving from 'Development' to 'Production' have an associated Runbook link populated in the Notable Event.

    Where should this link be configured in the Correlation Search editor?

    Show answer details

    Correct answer: D

    The 'Next Steps' field in the Correlation Search definition is specifically designed to provide analysts with immediate guidance, such as a URL to a wiki or runbook.

  4. 4

    Which Splunk command is most efficient for summarizing large volumes of data within a Data Model to be used in high-performance dashboards?

    Show answer details

    Correct answer: C

    tstats is designed to query the accelerated summary files (tsidx) of a data model directly, making it exponentially faster than stats or transaction which must read raw events from disk.

  5. 5

    A Detection Engineer is building a process to validate new detections.

    Which of the following describes the 'purple team' approach to validation?

    Show answer details

    Correct answer: D

    Purple teaming involves collaboration where the Red team (offense) executes attacks specifically to test if the Blue team (defense) can detect them, allowing for immediate feedback and tuning.

  6. 6

    A Security Operations Center (SOC) is onboarding logs from a custom legacy firewall. The raw logs contain the action 'permit' or 'block', but the Splunk Common Information Model (CIM) requires the field 'action' to contain 'allowed' or 'blocked'.

    Which configuration method should the engineer use to normalize this data efficiently without altering the raw data?

    Show answer details

    Correct answer: C

    Using a lookup file is the standard and most efficient way to map vendor-specific field values (like 'permit') to CIM-compliant values (like 'allowed') without modifying the underlying raw data (which SEDCMD would do) or creating complex calculated fields.

  7. 7

    An engineer is troubleshooting a correlation search that utilizes the tstats command against a data model. The search is returning zero results despite raw data being present in the index. The data model acceleration summary shows as 100% complete.

    Which of the following is the most likely cause for the missing results?

    Show answer details

    Correct answer: C

    The tstats command requires strict adherence to the data model hierarchy (e.g., datamodel=Network_Traffic nodename=All_Traffic.Traffic_By_Action). If the nodename is incorrect or references a non-existent child dataset, tstats will return zero results even if acceleration is built.

  8. 8

    A Defense Engineer needs to implement a Risk-Based Alerting (RBA) strategy. They want to assign risk scores to users based on observed suspicious behaviors without triggering an immediate alert for every single event.

    Which type of correlation search should be configured to accomplish this?

    Show answer details

    Correct answer: B

    In RBA, the primary mechanism is to create correlation searches that do NOT generate Notable Events directly but instead use the 'Risk Analysis' adaptive response action. This action adds entries to the risk index, incrementing the risk score for the associated risk object (e.g., user or system).

  9. 9

    Review the following Mermaid diagram representing a Risk-Based Alerting (RBA) workflow:

    flowchart LR A[Raw Events] --> B{Correlation Search} B -->|Match| C[Risk Analysis Action] C --> D[Risk Index] D --> E{Risk Incident Rule} E -->|Threshold Met| F[Notable Event]

    At which stage in this workflow are 'Risk Modifiers' applied to the Risk Object?

    Show answer details

    Correct answer: C

    Risk Modifiers (score and message) are applied during the Risk Analysis Action (Stage C). This action takes the context from the detection and writes it to the Risk Index (Stage D) as a modifier to the object's score.

  10. 10

    A Splunk SOAR engineer is designing a playbook to handle phishing investigations. The playbook needs to extract all URLs from the email body and then check each URL against a reputation service.

    Which two playbook blocks are essential to achieve this workflow? (Select TWO)

    Show answer details

    Correct answer: B, C

    An Action Block is required to execute the reputation check (e.g., 'url_reputation') against the extracted URLs.

    A Utility Block (specifically using an API or custom code) is often used to parse or extract specific artifacts like URLs from a text body if not automatically done by ingestion. Alternatively, a 'Format' or 'Code' block (types of utilities) handles data manipulation.

Create an account to continue.