Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 1Objective 1

Summarize the Organization of a Typical SOC and the Tasks Belonging to Analyst, Engineer and Architect Roles. SPLK-5001 Practice Questions (Page 2)

Part of the The Cyber Landscape, Frameworks, and Standards domain, which accounts for 10% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
5concepts
10%of the exam

Questions 6–10

  1. 6expert · hard

    A SOC analyst discovers a series of alerts indicating that a legitimate internal application is making outbound connections to an IP address that is on a threat intelligence blocklist. The analyst verifies that the application is business-critical and that the IP is a shared hosting address that may also serve legitimate services. The analyst must decide how to handle the alerts without disrupting business operations. What is the most appropriate action?

    Select an answer first
  2. 7application · medium

    A Tier 1 SOC analyst is monitoring the SIEM dashboard and sees an alert for a user logging in from an unusual geographic location at 3:00 AM. The analyst checks the user's profile and sees they are a remote worker who frequently travels. The user has not been flagged by any other rule. What is the most appropriate action for the analyst?

    Select an answer first
  3. 8application · medium

    A Tier 2 SOC analyst is investigating a confirmed malware infection on a server. The analyst has identified the malicious process and the files it created. According to typical SOC role definitions, which task is most appropriate for the Tier 2 analyst to perform?

    Select an answer first
  4. 9application · medium

    A SOC analyst notices an alert for a single workstation attempting outbound connections to a known malicious IP. The alert fired at 2:00 AM, and the workstation user has not logged in since yesterday. The analyst checks the endpoint logs, confirms the connection was initiated by a scheduled task, and determines the file is quarantined. According to typical SOC tier structure, which action is most appropriate for this analyst to take next?

    Select an answer first
  5. 10application · medium

    A SOC architect is planning a new SOC for a financial institution that must comply with strict data residency requirements. The architect needs to design the architecture to ensure that all security logs are stored within the country of operation. Which consideration is most important for the architect to address?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.