Splunk Certified Cybersecurity Defense Engineer Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 250 questions. Use the simulator for timed and flashcard mode.

Try Simulator

SPLK-5002 Sample Questions

  1. Question 1

    Q1

    A Security Operations Center (SOC) is onboarding logs from a custom legacy firewall. The raw logs contain the action 'permit' or 'block', but the Splunk Common Information Model (CIM) requires the field 'action' to contain 'allowed' or 'blocked'.

    Which configuration method should the engineer use to normalize this data efficiently without altering the raw data?

    Show answer & explanation

    Correct answer: B

    Using a lookup file is the standard and most efficient way to map vendor-specific field values (like 'permit') to CIM-compliant values (like 'allowed') without modifying the underlying raw data (which SEDCMD would do) or creating complex calculated fields.

  2. Question 2

    Q2

    An engineer is troubleshooting a correlation search that utilizes the tstats command against a data model. The search is returning zero results despite raw data being present in the index. The data model acceleration summary shows as 100% complete.

    Which of the following is the most likely cause for the missing results?

    Show answer & explanation

    Correct answer: B

    The tstats command requires strict adherence to the data model hierarchy (e.g., datamodel=Network_Traffic nodename=All_Traffic.Traffic_By_Action). If the nodename is incorrect or references a non-existent child dataset, tstats will return zero results even if acceleration is built.

  3. Question 3

    Q3

    A Defense Engineer needs to implement a Risk-Based Alerting (RBA) strategy. They want to assign risk scores to users based on observed suspicious behaviors without triggering an immediate alert for every single event.

    Which type of correlation search should be configured to accomplish this?

    Show answer & explanation

    Correct answer: A

    In RBA, the primary mechanism is to create correlation searches that do NOT generate Notable Events directly but instead use the 'Risk Analysis' adaptive response action. This action adds entries to the risk index, incrementing the risk score for the associated risk object (e.g., user or system).

  4. Question 4

    Q4

    Review the following Mermaid diagram representing a Risk-Based Alerting (RBA) workflow:

    flowchart LR A[Raw Events] --> B{Correlation Search} B -->|Match| C[Risk Analysis Action] C --> D[Risk Index] D --> E{Risk Incident Rule} E -->|Threshold Met| F[Notable Event]

    At which stage in this workflow are 'Risk Modifiers' applied to the Risk Object?

    Show answer & explanation

    Correct answer: B

    Risk Modifiers (score and message) are applied during the Risk Analysis Action (Stage C). This action takes the context from the detection and writes it to the Risk Index (Stage D) as a modifier to the object's score.

  5. Question 5

    Q5Multiple answers

    A Splunk SOAR engineer is designing a playbook to handle phishing investigations. The playbook needs to extract all URLs from the email body and then check each URL against a reputation service.

    Which two playbook blocks are essential to achieve this workflow? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    An Action Block is required to execute the reputation check (e.g., 'url_reputation') against the extracted URLs.

    A Utility Block (specifically using an API or custom code) is often used to parse or extract specific artifacts like URLs from a text body if not automatically done by ingestion. Alternatively, a 'Format' or 'Code' block (types of utilities) handles data manipulation.

  6. Question 6

    Q6

    When integrating Splunk Enterprise Security (ES) with Splunk SOAR, an administrator wants to ensure that when a Notable Event's status is changed to 'Closed' in ES, the corresponding container in SOAR is also closed automatically.

    Which feature must be configured to enable this synchronization?

    Show answer & explanation

    Correct answer: C

    The Splunk App for SOAR Export (or Phantom App) configured on the search head allows for bidirectional synchronization. This ensures that status changes in ES notables are reflected in SOAR containers, and vice versa.

  7. Question 7

    Q7

    A detection engineer is reviewing the efficacy of a specific correlation search. They notice that the search generates a high volume of alerts for a specific administrative subnet (10.10.5.0/24) performing legitimate scanning activities.

    What is the most effective way to suppress these specific alerts without disabling the detection for the rest of the network?

    Show answer & explanation

    Correct answer: B

    Using a managed lookup for whitelisting is the best practice. It separates the detection logic from the exclusion data, making it easier to maintain and audit changes to the whitelist without editing the core SPL of the correlation search.

  8. Question 8

    Q8

    True or False: In Splunk Enterprise Security, the Asset and Identity frameworks can automatically enrich notable events with departmental information, but they cannot effectively prioritize alerts based on the 'criticality' field of an asset.

    Show answer & explanation

    Correct answer: B

    This is False. The Asset and Identity frameworks are explicitly designed to prioritize alerts. By defining the 'priority' or 'criticality' category for assets (e.g., PCI servers, C-level laptops), ES can calculate a higher urgency for Notable Events involving those assets.

  9. Question 9

    Q9

    A security manager requires a monthly report detailing the 'Mean Time to Detect' (MTTD) and 'Mean Time to Respond' (MTTR) for the SOC.

    Which Splunk Enterprise Security dashboard provides these metrics out-of-the-box?

    Show answer & explanation

    Correct answer: B

    The SOC Operations dashboard (sometimes labeled Incident Review Operations in newer versions) specifically tracks the efficiency of the SOC, including key performance indicators like MTTD, MTTR, and investigations per analyst.

  10. Question 10

    Q10

    You are creating a new correlation search to detect 'Brute Force Access' attempts. You want to ensure that if the search runs every 5 minutes and detects an attack, it creates a Notable Event, but does NOT create another duplicate event for the same user and destination for at least 1 hour.

    Which configuration setting handles this requirement?

    Show answer & explanation

    Correct answer: C

    Window Throttling (configured in the correlation search editor) allows you to suppress subsequent alerts based on a set of fields (e.g., user, dest) for a specified duration (e.g., 1 hour), preventing alert fatigue.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the SPLK-5002 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon