Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Analyst

Domain 4Objective 6

Understand and Explain the Essentials of Risk Based Alerting, the Risk Framework and Creating Correlation Searches Within Enterprise Security. SPLK-5001 Practice Questions (Page 5)

Part of the Investigation, Event Handling, Correlation, and Risk domain, which accounts for 20% of the SPLK-5001 exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
8concepts
20%of the exam

Questions 21–25

  1. 21expert · hard

    A SOC is implementing RBA and has set a risk threshold of 80 for users. They have a correlation search that adds 20 risk points for each failed login. A user has had 3 failed logins in the past hour, bringing their risk score to 60. The SOC wants to be alerted when the user's risk score reaches 80. What is the most effective way to achieve this?

    Select an answer first
  2. 22foundation · easy

    Which of the following is a key component of the Risk framework in Splunk Enterprise Security?

    Select an answer first
  3. 23foundation · easy

    Which of the following is an example of an alert action that can be configured for a correlation search?

    Select an answer first
  4. 24application · medium

    A Splunk admin is tuning the Risk framework. They notice that a user's risk score is increasing faster than expected. They want to understand how the risk score is calculated. Which statement accurately describes risk score calculation in the Risk framework?

    Select an answer first
  5. 25foundation · easy

    How can a correlation search contribute to the Risk framework in Splunk Enterprise Security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-5001” is a trademark of its owner, used for identification only.