Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 4Objective 3

Demonstrate Ability to Recognize Common Event Dispositions and Correctly Assign Them. SPLK-5001 Practice Questions (Page 1)

Part of the Investigation, Event Handling, Correlation, and Risk domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 11 practice questions to prepare you well beyond it. (estimate)

11questions here
3free pages
3concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    A junior analyst investigates an alert for 'New Admin Account Created' and finds that a new account was indeed created with admin privileges. However, the analyst cannot determine whether the account creation was authorized because the change-management ticket referenced in the alert is not yet approved. The analyst has exhausted all available log sources and cannot reach a conclusion. Which disposition should be assigned?

    Select an answer first
  2. 2foundation · easy

    What is the first step an analyst typically takes when assigning a disposition to an event in Splunk ES?

    Select an answer first
  3. 3foundation · easy

    In Splunk Enterprise Security, which event disposition is used when an investigation confirms that the activity is malicious and poses a genuine threat to the organization?

    Select an answer first
  4. 4foundation · easy

    Which Splunk ES event disposition is correctly matched with its definition?

    Select an answer first
  5. 5foundation · easy

    During an investigation, an analyst finds that an alert was triggered by a misconfigured security tool that generated a log entry for a normal administrative login. The login was legitimate and expected. Which disposition should be assigned?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.