Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 2Objective 2

Define Common Terms Including Supply Chain Attack, Ransomware, Registry, Exfiltration, Social Engineering, DoS, DDoS, Bot and Botnet, C2, Zero Trust, Account Takeover, Email Compromise, Threat Actor, APT, Adversary. SPLK-5001 Practice Questions (Page 6)

Part of the Threat and Attack Types, Motivations, and Tactics domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
15concepts
20%of the exam

Questions 26–30

  1. 26application · medium

    An organization has been under continuous attack for over a year. The attackers use highly customized tools, maintain persistent access to the network, and have exfiltrated sensitive data over a long period. The attack is well-resourced and appears to be state-sponsored. Which term best describes this campaign?

    Select an answer first
  2. 27foundation · easy

    What is account takeover?

    Select an answer first
  3. 28foundation · easy

    What is the primary goal of an attacker in a supply chain attack?

    Select an answer first
  4. 29expert · hard

    A company is transitioning to a zero trust model. The security team is evaluating how to handle access requests from employees working remotely. The team wants to ensure that every access request is verified, regardless of the user's location. Which control is most aligned with the zero trust principle?

    Select an answer first
  5. 30foundation · easy

    Which activity is an example of data exfiltration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.