
Splunk Certified Cybersecurity Defense Analyst
The Splunk Certified Cybersecurity Defense Analyst certification validates your ability to detect, analyze, and combat cyber threats using Splunk Enterprise and Enterprise Security. Designed for SOC analysts and cybersecurity professionals, it demonstrates hands-on skills in threat hunting, risk-based alerting, and continuous monitoring. Earning this credential proves you can help protect businesses and mitigate risk with industry best practices.
562 practice questions · Updated 2026-07-30
6Domains
24Objectives
134Concepts
562Questions
SPLK-5001 Curriculum
Every domain, objective, and concept the SPLK-5001 exam measures.
- SOC Organizational Structure
- SOC Roles and Responsibilities
- SOC Analyst Tasks
- SOC Engineer Tasks
- SOC Architect Tasks
- Common industry controls
- Common industry standards
- Common industry frameworks
- Splunk framework incorporation
- Confidentiality
- Integrity
- Availability
- CIA Triad
- Risk Management Basics
- Risk Terminology
- Risk Assessment Process
- Attack Vectors
- Attack Types
- Motivations Behind Attacks
- Tactics and Techniques
- Supply Chain Attack
- Ransomware
- Registry
- Exfiltration
- Social Engineering
- Denial of Service (DoS)
- Distributed Denial of Service (DDoS)
- Bot and Botnet
- Command and Control (C2)
- Zero Trust
- Account Takeover
- Email Compromise
- Threat Actor
- Advanced Persistent Threat (APT)
- Adversary
- Threat Intelligence Tiers Overview
- Strategic Threat Intelligence
- Tactical Threat Intelligence
- Operational Threat Intelligence
- Applying Threat Intelligence Tiers to Analysis
- Purpose of annotations
- Scope of annotations
- Definition of TTPs
- Industry Perspective on TTPs
- Use of TTPs in Threat Intelligence
- TTPs in Detection and Response
- Cyber defense system categories
- Analysis tools for threat detection
- Data sources for threat analysis
- Mapping data sources to defense systems
- SIEM Best Practices
- Splunk Enterprise Security Overview
- Common Information Model (CIM)
- Data Models and Acceleration
- Asset and Identity Frameworks
- Common CIM Fields in Investigations
- Splunk Security Essentials overview
- Splunk Enterprise Security overview
- Common sourcetypes for on-prem deployments
- Common sourcetypes for cloud deployments
- Using Splunk Security Essentials to assess data sources
- Using Splunk Enterprise Security to assess data sources
- Finding content for a given sourcetype
- Continuous Monitoring Definition
- Continuous Monitoring Implementation
- Five Basic Stages of Investigation
- Stage 1: Triage
- Stage 2: Investigation
- Stage 3: Containment
- Stage 4: Eradication
- Stage 5: Recovery
- Application of Stages
- Define MTTR
- Define dwell time
- Distinguish MTTR and dwell time
- Explain the importance of these metrics
- Common Event Dispositions
- Disposition Assignment Criteria
- Disposition Workflow
- SPL Basics
- Notable Event Definition
- Risk Notable Definition
- Adaptive Response Action Definition
- Risk Object Definition
- Contributing Events Definition
- Use Cases in Splunk ES
- Identify built-in dashboards
- Understand dashboard purpose
- Describe dashboard content
- Navigate dashboards
- Risk-Based Alerting (RBA) fundamentals
- Risk framework components
- Risk score calculation
- Risk notables and incident generation
- Correlation search basics
- Creating correlation searches
- Correlation search configuration options
- Integrating RBA with correlation searches
- TSTATS
- TRANSACTION
- FIRST and LAST
- REX
- EVAL
- FOREACH
- LOOKUP
- MAKERESULTS
- Search optimization principles
- Time range selection
- Index and source type filtering
- Field-based filtering
- Efficient use of search commands
- Avoiding wildcards and leading wildcards
- Using summary indexing and reports
- Search job inspection
- Search mode optimization
- Using tstats for accelerated data
- Identify SPL resources in ES
- Identify SPL resources in Splunk Security Essentials
- Differentiate SPL resources between ES and SSE
- Threat Hunting Configuration
- Modeling Anomalies
- Indicators of Compromise (IOCs)
- Behavioral Analytics
- Long Tail Analysis
- Outlier Detection
- Hypothesis Hunting Overview
- Steps of Hypothesis Hunting
- Applying Long Tail and Outlier Detection in Splunk
- Adaptive Response Actions Overview
- When to Use Adaptive Response Actions
- Configuring Adaptive Response Actions
- Testing and Validating Adaptive Response Actions
- SOAR playbook fundamentals
- Playbook triggers in Enterprise Security
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for SPLK-5001, so none is invented.