
SplunkCertified Cybersecurity Defense Analyst
Domain 4Objective 3
Demonstrate Ability to Recognize Common Event Dispositions and Correctly Assign Them. SPLK-5001 Practice Questions (Page 1)
Part of the Investigation, Event Handling, Correlation, and Risk domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 11 practice questions to prepare you well beyond it. (estimate)
11questions here
3free pages
3concepts
20%of the exam
Questions 1–5
- 1
A junior analyst investigates an alert for 'New Admin Account Created' and finds that a new account was indeed created with admin privileges. However, the analyst cannot determine whether the account creation was authorized because the change-management ticket referenced in the alert is not yet approved. The analyst has exhausted all available log sources and cannot reach a conclusion. Which disposition should be assigned?
Select an answer first - 2
What is the first step an analyst typically takes when assigning a disposition to an event in Splunk ES?
Select an answer first - 3
In Splunk Enterprise Security, which event disposition is used when an investigation confirms that the activity is malicious and poses a genuine threat to the organization?
Select an answer first - 4
Which Splunk ES event disposition is correctly matched with its definition?
Select an answer first - 5
During an investigation, an analyst finds that an alert was triggered by a misconfigured security tool that generated a log entry for a normal administrative login. The login was legitimate and expected. Which disposition should be assigned?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.