Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 3Objective 3

Describe How Splunk Security Essentials and Splunk Enterprise Security Can Be Used to Assess Data Sources, Including Common Sourcetypes for On-Prem and Cloud Based Deployments and How to Find Content for a Given Sourcetype. SPLK-5001 Practice Questions (Page 3)

Part of the Defenses, Data Sources, and SIEM Best Practices domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
20%of the exam

Questions 11–15

  1. 11expert · hard · select all that apply

    A security team is ingesting data from multiple cloud sources into Splunk Enterprise Security. The team wants to use the Data Sources page to assess the health of their cloud data sources and then find relevant content in Splunk Security Essentials. The team is currently ingesting AWS CloudTrail, Azure Activity Log, and Google Workspace. Select all the sourcetypes that the team should expect to see in the Data Sources page for these cloud sources.

    Select an answer first
  2. 12foundation · easy

    In Splunk Security Essentials, what does the 'Data Source Coverage' view help you do?

    Select an answer first
  3. 13application · medium

    A company runs a traditional on-premises data center with Windows servers, Cisco ASA firewalls, and a custom Java application. The security team is using Splunk Security Essentials to assess their data source coverage. Which set of sourcetypes would the assessment most likely identify as expected for these three on-premises components?

    Select an answer first
  4. 14foundation · easy

    Which sourcetype is commonly used for AWS CloudTrail logs?

    Select an answer first
  5. 15application · medium

    A security analyst is setting up monitoring for a new Microsoft 365 deployment. The analyst has configured the Office 365 add-on and confirmed that data is flowing into Splunk. The analyst wants to find existing Splunk Security Essentials content (such as correlation searches and dashboards) that is specifically designed for the Office 365 sourcetype. Which approach should the analyst use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.