
SplunkCertified Cybersecurity Defense Analyst
Domain 2Objective 2
Define Common Terms Including Supply Chain Attack, Ransomware, Registry, Exfiltration, Social Engineering, DoS, DDoS, Bot and Botnet, C2, Zero Trust, Account Takeover, Email Compromise, Threat Actor, APT, Adversary. SPLK-5001 Practice Questions (Page 4)
Part of the Threat and Attack Types, Motivations, and Tactics domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
15concepts
20%of the exam
Questions 16–20
- 16
What is a threat actor?
Select an answer first - 17
What is a bot in the context of cybersecurity?
Select an answer first - 18
Which of the following best describes the role of the Windows registry?
Select an answer first - 19
An analyst at a hospital notices that patient records on several servers have been encrypted with a .locked extension, and a ransom note demands payment in cryptocurrency for the decryption key. The analyst also observes that some files were transferred to an external IP before encryption began. Which two attack characteristics are present in this scenario?
Select an answer first - 20
An analyst discovers that a group of compromised computers in the organization is receiving instructions from a remote server and participating in coordinated spam campaigns. Which term best describes the individual compromised computers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.