
SplunkCertified Cybersecurity Defense Analyst
Domain 6Objective 3
Determine When to Use Adaptive Response Actions and Configure Them as Needed. SPLK-5001 Practice Questions (Page 4)
Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
10%of the exam
Questions 16–20
- 16
A Splunk admin is configuring an adaptive response action to send an email notification when a notable event is created. The admin wants to ensure the notification is sent only for events with a severity of 'high' or 'critical'. What should the admin configure?
Select an answer first - 17
An analyst configures an adaptive response action to send an email notification when a notable event is created. During testing, the analyst finds that the email is not sent. The analyst verifies that the SMTP server is reachable and the email settings are correct. What should the analyst check next?
Select an answer first - 18
A security analyst detects a suspicious outbound connection from a critical server to a known C2 domain. The organization's policy requires immediate containment of the affected host while preserving forensic evidence. The analyst has already confirmed the alert is a true positive. Which adaptive response action should be configured to meet the containment requirement?
Select an answer first - 19
An analyst is investigating a low-severity alert that indicates a user visited a known phishing site. The organization's policy states that low-severity alerts should be monitored but not automatically remediated. Which adaptive response action is most appropriate?
Select an answer first - 20
A security analyst is investigating a notable event for a potential insider threat. The organization's policy requires that any confirmed insider threat trigger an automatic lockout of the user's account, but only if the user is not a member of the executive team. The executive team is defined in an Active Directory group. Which adaptive response action should be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SPLK-5001
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.