
SplunkCertified Cybersecurity Defense Analyst
Domain 6Objective 3
Determine When to Use Adaptive Response Actions and Configure Them as Needed. SPLK-5001 Practice Questions (Page 3)
Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
10%of the exam
Questions 11–15
- 11
A Splunk admin is configuring an adaptive response action to enrich a notable event with threat intelligence from an external API. The admin wants to ensure the action only runs when the event contains a specific field. What should the admin configure?
Select an answer first - 12
A security operations center (SOC) receives a high-severity alert for a potential ransomware infection on a user's endpoint. The organization's incident response plan requires immediate isolation of the endpoint to prevent lateral movement. Which adaptive response action should be configured?
Select an answer first - 13
A Splunk admin configures an adaptive response action to block a malicious IP on a firewall via API. Before enabling it in production, the admin wants to validate that the action works correctly without affecting live traffic. Which approach should the admin take?
Select an answer first - 14
A Splunk admin configures an adaptive response action to run a script that blocks a user's account. During testing, the admin triggers the correlation search and the action appears to run, but the account is not blocked. The admin checks the script's logs and sees an error about a missing parameter. What is the most likely cause?
Select an answer first - 15
When configuring an adaptive response action in Splunk, what must you specify?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.