
SplunkCertified Cybersecurity Defense Analyst
Domain 2Objective 4
Outline the Purpose and Scope of Annotations Within Splunk Enterprise Security. SPLK-5001 Practice Questions (Page 3)
Part of the Threat and Attack Types, Motivations, and Tactics domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
2concepts
20%of the exam
Questions 11–15
- 11
An analyst wants to add an annotation to a notable event that includes the affected user's role, the department, and a note about the user's recent activity. What is the most efficient way to capture this information?
Select an answer first - 12
A security analyst is investigating a notable event involving a compromised user account. The analyst has confirmed the compromise through multiple data sources and wants to document the findings directly on the notable event so that the next analyst on shift can understand the investigation without redoing the work. Which action should the analyst take?
Select an answer first - 13
A security analyst is working on a notable event and wants to add a hyperlink to an external threat intelligence report for reference. What should the analyst do?
Select an answer first - 14
A security analyst is reviewing a notable event and notices that the event was annotated by a previous analyst with a note saying 'False positive - user was on VPN.' The current analyst wants to verify this claim before closing the event. What is the most appropriate action?
Select an answer first - 15
In Splunk Enterprise Security, which type of information can be captured in an annotation on a notable event?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SPLK-5001
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.