
SplunkCertified Cybersecurity Defense Analyst
Domain 2Objective 2
Define Common Terms Including Supply Chain Attack, Ransomware, Registry, Exfiltration, Social Engineering, DoS, DDoS, Bot and Botnet, C2, Zero Trust, Account Takeover, Email Compromise, Threat Actor, APT, Adversary. SPLK-5001 Practice Questions (Page 8)
Part of the Threat and Attack Types, Motivations, and Tactics domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
15concepts
20%of the exam
Questions 36–40
- 36
A small business's website becomes unresponsive after a single attacker sends a massive flood of requests from one compromised machine. The attack is traced back to a single IP address. Which term best describes this attack?
Select an answer first - 37
In cybersecurity, how is the term 'adversary' most commonly used?
Select an answer first - 38
What is the Windows registry?
Select an answer first - 39
Which principle is central to the zero trust model?
Select an answer first - 40
An incident responder is handling a ransomware incident where files have been encrypted and a ransom note demands payment. During the investigation, the responder discovers that some sensitive files were exfiltrated before encryption. The organization's leadership is considering paying the ransom to recover data and prevent the release of the exfiltrated data. Which consideration is most important when advising leadership on this decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.