Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 3Objective 3

Describe How Splunk Security Essentials and Splunk Enterprise Security Can Be Used to Assess Data Sources, Including Common Sourcetypes for On-Prem and Cloud Based Deployments and How to Find Content for a Given Sourcetype. SPLK-5001 Practice Questions (Page 2)

Part of the Defenses, Data Sources, and SIEM Best Practices domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
20%of the exam

Questions 6–10

  1. 6expert · hard

    A Splunk Enterprise Security administrator is responsible for a hybrid environment with on-premises Windows servers, Linux servers, and Cisco ASA firewalls, plus AWS CloudTrail and GuardDuty. The administrator notices that the 'Endpoint' data source category shows a low health score, while the 'Network' and 'Cloud' categories appear healthy. The administrator suspects that some Windows event logs are not being collected. The administrator wants to confirm which specific Windows sourcetypes are missing and then determine which Splunk Security Essentials content would be affected. Which sequence of actions should the administrator take?

    Select an answer first
  2. 7application · medium

    A security analyst is investigating a potential brute-force attack on a Windows server. The analyst knows that Windows security logs are being ingested with the sourcetype 'WinEventLog:Security'. The analyst wants to find existing correlation searches in Splunk Security Essentials that are specifically designed for this sourcetype to detect brute-force attempts. Which method should the analyst use?

    Select an answer first
  3. 8application · medium

    A small security team is new to Splunk and has just started ingesting Windows event logs and Linux syslog from their on-premises servers. They want to understand which security use cases they can currently detect with the data they have, and which use cases require additional data sources. The team does not yet have Splunk Enterprise Security installed. Which tool should they use to perform this gap analysis?

    Select an answer first
  4. 9foundation · easy

    Which sourcetype is commonly used for network device logs from firewalls and routers?

    Select an answer first
  5. 10expert · hard · select all that apply

    A security team is evaluating whether to use Splunk Security Essentials to assess their on-premises data sources. The team currently ingests Windows security logs, Linux syslog, and Cisco ASA firewall logs. They want to use Splunk Security Essentials to identify gaps in their security coverage. Select all the actions that Splunk Security Essentials can perform to help the team achieve this goal.

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.