
SplunkCertified Cybersecurity Defense Analyst
Domain 6Objective 4
Explain the Use of SOAR Playbooks and List the Basic Ways They Can Be Triggered from Enterprise Security. SPLK-5001 Practice Questions (Page 3)
Part of the Threat Hunting and Remediation domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
2concepts
10%of the exam
Questions 11–15
- 11
A SOC team is using Splunk Enterprise Security and SOAR. They have a playbook that is triggered by an Adaptive Response action from a correlation search. The playbook is supposed to block a malicious IP at the firewall. However, the team notices that the playbook is not triggering at all. The correlation search is generating notable events, and the playbook is published. What is the most likely cause of the playbook not triggering?
Select an answer first - 12
Which Enterprise Security feature allows a SOAR playbook to be launched automatically when a notable event is created?
Select an answer first - 13
A security analyst is manually running a SOAR playbook from a notable event in Enterprise Security. The playbook is designed to block a malicious domain. However, the analyst notices that the playbook is not appearing in the 'Run Playbook' action menu. The playbook is published and associated with the 'notable' container type. What is the most likely reason for this?
Select an answer first - 14
A SOC team is designing a SOAR playbook for a 'Ransomware Detected' notable event. The playbook should perform the following actions in order: 1) Isolate the endpoint, 2) Block the ransomware hash, 3) Notify the incident response team. The team wants to ensure that if the isolation step fails, the playbook still attempts to block the hash and send the notification. What is the best way to configure the playbook?
Select an answer first - 15
A large enterprise has a SOAR playbook that is triggered automatically by a correlation search for 'Malware Detected' notable events. The playbook isolates the affected endpoint and blocks the associated file hash. Recently, the SOC team has noticed that the playbook is isolating endpoints that are part of a critical business application, causing significant downtime. They want to prevent this while still automating the response for non-critical endpoints. What is the most effective way to modify the playbook to address this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.