Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 6Objective 2

Define Long Tail Analysis, Outlier Detection, and Some Common Steps of Hypothesis Hunting with Splunk. SPLK-5001 Practice Questions (Page 3)

Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts
10%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst is reviewing authentication logs and wants to identify rarely used service accounts that have recently become active, because these could indicate compromised credentials. The analyst needs a Splunk search that surfaces accounts with very few total logon events but that have logged on within the last 24 hours. Which approach best accomplishes this?

    Select an answer first
  2. 12application · medium

    A Splunk analyst is hunting for signs of data exfiltration and wants to identify files that are rarely accessed but have recently been copied to external drives. The analyst has a baseline of file access counts over the past year. Which Splunk search strategy best combines long tail analysis and outlier detection to surface these files?

    Select an answer first
  3. 13application · medium

    A threat hunting team wants to proactively identify potential insider threats by looking for employees who access systems they do not normally use. The team plans to use Splunk to analyze access logs. Which of the following best describes the role of hypothesis hunting in this scenario?

    Select an answer first
  4. 14application · medium

    A Splunk analyst is monitoring the number of failed logon attempts per user per day. The analyst wants to flag users whose failed logon count is significantly higher than their own historical average. Which approach is most appropriate?

    Select an answer first
  5. 15application · medium

    An analyst is reviewing VPN login times for a user who typically connects between 8 AM and 6 PM. The analyst notices a login at 2:47 AM and wants to determine if this is truly anomalous. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.