Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 6Objective 4

Explain the Use of SOAR Playbooks and List the Basic Ways They Can Be Triggered from Enterprise Security. SPLK-5001 Practice Questions (Page 1)

Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)

16questions here
4free pages
2concepts
10%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst is creating a new SOAR playbook to handle phishing emails reported by users. The playbook should extract the URL from the email, check it against a threat intelligence service, and if malicious, block the URL and notify the user. What is the correct sequence of steps in the playbook?

    Select an answer first
  2. 2application · medium

    An organization has a SOAR playbook that is triggered automatically by a correlation search in Enterprise Security. The playbook is designed to disable a compromised user account. However, the SOC team wants to add a manual approval step before the account is actually disabled. How can this be achieved within the playbook?

    Select an answer first
  3. 3foundation · easy

    In Splunk SOAR, what is the primary purpose of a playbook?

    Select an answer first
  4. 4expert · hard

    An organization is implementing SOAR playbooks to automate incident response. They have a playbook that handles 'Account Compromise' events. The playbook currently disables the user account and resets the password. The SOC team wants to add a step to notify the user's manager, but only if the user is a high-privilege account. They also want to ensure that if the notification fails, the playbook still completes successfully. How should the playbook be designed?

    Select an answer first
  5. 5application · medium

    A security analyst is working in Splunk Enterprise Security and has identified a notable event that requires immediate action. They want to run a specific SOAR playbook that is not currently associated with the notable event's default action menu. What is the most efficient way for the analyst to run this playbook?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.