Free Splunk SPLK-5001 practice questions

10 free Splunk SPLK-5001 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 131 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which Enterprise Security framework provides a mechanism for running preconfigured actions within the Splunk platform or integrating with external applications?

  1. Asset and Identity
  2. Notable Event
  3. Threat Intelligence
  4. Adaptive Response
Show answer and explanation

Correct answer: D. Adaptive Response

Adaptive Response is the Enterprise Security framework feature that provides a mechanism for running preconfigured actions within Splunk or integrating with external applications. It allows automated response actions to be triggered based on correlation search results, enabling both internal Splunk actions and third-party integrations.

Why the other options are wrong

  • A. Asset and Identity provides data enrichment and contextualization but does not handle automated response actions.
  • B. Notable Event is a concept for alerting on significant security events but is not a framework for running preconfigured actions.
  • C. Threat Intelligence provides threat data enrichment and context but is not the mechanism for running response actions.

Question 2

Which of the following Splunk Enterprise Security features allows industry frameworks such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain® to be mapped to Correlation Search results?

  1. Annotations
  2. Playbooks
  3. Comments
  4. Enrichments
Show answer and explanation

Correct answer: A. Annotations

Annotations in Splunk Enterprise Security allow industry frameworks and security standards such as CIS Critical Security Controls, MITRE ATT&CK, and the Lockheed Martin Cyber Kill Chain to be mapped and associated with Correlation Search results. This provides context and compliance mapping for security findings.

Why the other options are wrong

  • B. Playbooks are automated response workflows, not mapping mechanisms for framework alignment.
  • C. Comments are general notes added to events but are not a structured feature for framework mapping.
  • D. Enrichments add contextual data to events but do not provide structured mapping to security frameworks.

Question 3

Which of the following is the primary benefit of using the CIM in Splunk?

  1. It allows for easier correlation of data from different sources.
  2. It improves the performance of search queries on raw data.
  3. It enables the use of advanced machine learning algorithms.
  4. It automatically detects and blocks cyber threats.
Show answer and explanation

Correct answer: A. It allows for easier correlation of data from different sources.

The primary benefit of the Common Information Model (CIM) in Splunk is that it allows for easier correlation of data from different sources. CIM provides a standardized field naming convention and data structure that enables consistent analysis across heterogeneous data sources regardless of their origin.

Why the other options are wrong

  • B. Performance on raw data is determined by index structure and query optimization, not CIM.
  • C. While CIM enables analytics, it does not specifically enable machine learning algorithms.
  • D. CIM is a data modeling framework; threat detection and blocking are functional outcomes that depend on correlation searches and response actions built on top of CIM.

Question 4

Tactics, Techniques, and Procedures (TTPs) are methods or behaviors utilized by attackers. In which framework are these categorized?

  1. NIST 800-53
  2. ISO 27000
  3. CIS18
  4. MITRE ATT&CK
Show answer and explanation

Correct answer: D. MITRE ATT&CK

Tactics, Techniques, and Procedures (TTPs) are categorized within the MITRE ATT&CK framework. MITRE ATT&CK provides a comprehensive knowledge base of adversary tactics and techniques based on real-world observations, organized hierarchically with tactics at the highest level and specific techniques and sub-techniques beneath them.

Why the other options are wrong

  • A. NIST 800-53 is a security controls framework, not a TTP categorization system.
  • B. ISO 27000 series addresses information security management but does not categorize TTPs.
  • C. CIS 18 refers to CIS Critical Security Controls, which are control recommendations rather than a TTP categorization framework.

Question 5

A threat hunter executed a hunt based on the following hypothesis:

As an actor, I want to plant rundll32 for proxy execution of malicious code and leverage Cobalt Strike for Command and Control.

Relevant logs and artifacts such as Sysmon, netflow, IDS alerts, and EDR logs were searched, and the hunter is confident in the conclusion that Cobalt Strike is not present in the company’s environment.

Which of the following best describes the outcome of this threat hunt?

  1. The threat hunt was successful because the hypothesis was not proven.
  2. The threat hunt failed because the hypothesis was not proven.
  3. The threat hunt failed because no malicious activity was identified.
  4. The threat hunt was successful in providing strong evidence that the tactic and tool is not present in the environment. ✅Correct Answer: A, The threat hunt was successful because the hypothesis was not proven. A threat hunt is measured by whether it reaches a defensible conclusion, not by whether it finds a threat. Here the hunter worked the hypothesis across Sysmon, netflow, IDS, and EDR data and concluded the activity was not there, so the hunt succeeded even though the hypothesis was not proven. Unproven hypotheses still deliver value by closing out a lead and validating visibility.
Show answer and explanation

Answer and explanation for question 5

Answer and explanation for question 5

Question 6

An analyst notices that one of their servers is sending an unusually large amount of traffic, gigabytes more than normal, to a single system on the Internet. There doesn’t seem to be any associated increase in incoming traffic.

What type of threat actor activity might this represent?

  1. Data exfiltration
  2. Network reconnaissance
  3. Data infiltration
  4. Lateral movement
Show answer and explanation

Correct answer: A. Data exfiltration

Large outbound traffic to an external system without corresponding inbound traffic is a classic indicator of data exfiltration. An attacker has likely compromised the server and is extracting sensitive data to an external location they control. The asymmetry in traffic direction and volume strongly suggests unauthorized data removal.

Why the other options are wrong

  • B. Network reconnaissance typically involves scanning and probing multiple systems, not sustained large data transfers to a single destination.
  • C. Data infiltration would manifest as incoming traffic from external sources, not outgoing traffic.
  • D. Lateral movement occurs between internal systems and would not necessarily show large volumes of traffic to a single external internet system.

Question 7

In which phase of the Continuous Monitoring cycle are suggestions and improvements typically made?

  1. Define and Predict
  2. Establish and Architect
  3. Analyze and Report
  4. Implement and Collect
Show answer and explanation

Correct answer: C. Analyze and Report

The Analyze and Report phase of the Continuous Monitoring cycle is where analysts examine collected data, identify patterns and anomalies, and generate reports with findings. Suggestions and improvements for the monitoring program are typically made during this phase based on analysis results and organizational needs.

Why the other options are wrong

  • A. Define and Predict involves planning and establishing the monitoring strategy, not making post-analysis improvements.
  • B. Establish and Architect focuses on building the monitoring infrastructure and baselines.
  • D. Implement and Collect is the execution phase where data is gathered, not where analysis-driven improvements are suggested.

Question 8

An analyst is not sure that all of the potential data sources at her company are being correctly or completely utilized by Splunk and Enterprise Security.

Which of the following might she suggest using, in order to perform an analysis of the data types available and some of their potential security uses?

  1. Splunk ITSI
  2. Splunk Security Essentials
  3. Splunk SOAR
  4. Splunk Intelligence Management
Show answer and explanation

Correct answer: B. Splunk Security Essentials

Splunk Security Essentials provides analysis and guidance on available data types, their security applications, and recommendations for optimizing data collection and utilization. It helps analysts understand potential data sources and their security use cases, making it ideal for assessing whether all organizational data is being properly leveraged.

Why the other options are wrong

  • A. Splunk ITSI (IT Service Intelligence) focuses on IT operations and performance monitoring, not security data source analysis.
  • C. Splunk SOAR (Security Orchestration, Automation and Response) is a platform for automating security response workflows, not analyzing available data sources.
  • D. Splunk Intelligence Management aggregates threat intelligence feeds; it does not analyze available data types or their security uses.

Question 9

During their shift, an analyst receives an alert about an executable being run from C: WindowsTemp.

Why should this be investigated further?

  1. Temp directories aren’t owned by any particular user, making it difficult to track the process owner when files are executed.
  2. Temp directories are flagged as non-executable, meaning that no files stored within can be executed, and this executable was run from that directory.
  3. Temp directories contain the system page file and the virtual memory file, meaning the attacker can use their malware to read the in memory values of running programs.
  4. Temp directories are world writable thus allowing attackers a place to drop, stage, and execute malware on a system without needing to worry about file permissions.
Show answer and explanation

Correct answer: D. Temp directories are world writable thus allowing attackers a place to drop, stage, and execute malware on a system without needing to worry about file permissions.

Temp directories like C:WindowsTemp are world-writable locations that do not require special permissions to write to, making them ideal locations for attackers to drop and stage malware before execution. This is a common technique in the attack chain because the low permission requirements allow malware to be placed and executed without needing elevated privileges or triggering permission-based alerts.

Why the other options are wrong

  • A. Temp directories can be tracked through file system logs and process execution logs that record which user context initiated the execution.
  • B. Temp directories are not flagged as non-executable; executables regularly run from these locations, which is precisely why this is suspicious.
  • C. Temp directories do not contain the system page file or virtual memory file; these are located elsewhere in the Windows system structure.

Question 10

An analyst would like to visualize threat objects across their environment and chronological risk events for a Risk Object in Incident Review.

Where would they find this?

  1. Running the Risk Analysis Adaptive Response action within the Notable Event.
  2. Via a workflow action for the Risk Investigation dashboard.
  3. Via the Risk Analysis dashboard under the Security Intelligence tab in Enterprise Security.
  4. Clicking the risk event count to open the Risk Event Timeline.
Show answer and explanation

Correct answer: D. Clicking the risk event count to open the Risk Event Timeline.

Timeline. Clicking the risk event count on a Risk Object in Incident Review opens the Risk Event Timeline, which provides a chronological visualization of risk events associated with that object across the environment. This is the standard interface within Splunk Enterprise Security for viewing the timeline and distribution of risk events.

Why the other options are wrong

  • A. Running the Risk Analysis Adaptive Response action generates analysis but does not provide the timeline visualization in the same manner.
  • B. Workflow actions for the Risk Investigation dashboard are separate from the risk event count visualization.
  • C. The Risk Analysis dashboard is found in Enterprise Security but the risk timeline specifically comes from clicking the event count in Incident Review.

That was 10 of 131.

The full Splunk SPLK-5001 pack has all 131 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack