
SplunkCertified Cybersecurity Defense Analyst
Domain 1Objective 2
Recognize Common Cyber Industry Controls, Standards and Frameworks and How Splunk Incorporates Those Frameworks. SPLK-5001 Practice Questions (Page 3)
Part of the The Cyber Landscape, Frameworks, and Standards domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
4concepts
10%of the exam
Questions 11–15
- 11
A risk manager wants to use a framework that organizes security activities into five high-level functions: Identify, Protect, Detect, Respond, and Recover. They want to use Splunk to support each function. Which framework is this?
Select an answer first - 12
A Splunk analyst uses the Splunk Enterprise Security (ES) framework to map security events to MITRE ATT&CK techniques. What is the primary benefit of mapping events to this framework?
Select an answer first - 13
Which standard specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS)?
Select an answer first - 14
A security team is implementing a new control to prevent lateral movement. They have two options: (1) deploy a host-based firewall on all endpoints, or (2) use Splunk to detect lateral movement after it occurs. The team has a limited budget and must choose one. Which approach is most aligned with a preventive control strategy?
Select an answer first - 15
A Splunk analyst uses Splunk Enterprise Security (ES) to monitor and alert on suspicious activity, which supports the 'Detect' function of the NIST Cybersecurity Framework. Which Splunk capability is most directly aligned with this function?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.