
SplunkCertified Cybersecurity Defense Analyst
Domain 6Objective 2
Define Long Tail Analysis, Outlier Detection, and Some Common Steps of Hypothesis Hunting with Splunk. SPLK-5001 Practice Questions (Page 4)
Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
10%of the exam
Questions 16–20
- 16
What is outlier detection in the context of cybersecurity data analysis?
Select an answer first - 17
A security team is reviewing proxy logs to find signs of command-and-control (C2) communication. They know that most users visit a small set of popular domains, but they want to focus on the many domains that are each visited very infrequently, because C2 domains often fall into that category. Which analytical approach is the team applying?
Select an answer first - 18
A Splunk analyst has formed the hypothesis that 'lateral movement is occurring via SMB from workstations to servers outside normal business hours.' The analyst has collected and analyzed the relevant SMB traffic and found several connections that match the hypothesis. What is the next step in the hypothesis hunting process?
Select an answer first - 19
A threat hunter has completed a hypothesis hunt and found a set of endpoints that appear to be beaconing to a known malicious domain. The hunter wants to ensure the findings are solid before escalating to incident response. Which action is most aligned with the validation step of hypothesis hunting?
Select an answer first - 20
A Splunk analyst wants to detect anomalous outbound connections from a web server. The analyst has a baseline of the number of outbound connections per hour over the past 60 days. Which Splunk search would be most effective for identifying an outlier hour?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.