SPLK-5001 practice questions
Splunk · SPLK-5001 · 300 questions
This practice test covers the Splunk SOAR Engineer certification exam. Test your knowledge across all domains and topics outlined in the official exam guide.
This course contains the use of artificial intelligence.
About the SPLK-5001 exam
- Exam fee
- $130 USD
- Time allowed
- 1 hour 15 minutes
- Questions
- 66
- Format
- Multiple choice, delivered by Pearson VUE; intermediate level.
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Threat and Attack Types, Motivations, and Tactics · 60 questions
- City employees click a fake timesheet-correction message that harvests Microsoft 365 passwords. What is the attack vector?
- A parking-kiosk vendor plugs an unmanaged laptop into the city VLAN and wormable malware spreads. What introduced the attack?
- Overnight logs show thousands of failed logons against the city's SSL-VPN used by public-works staff. How should the analyst classify this activity?
- Residents cannot reach the tax-assessor site, and netflow shows a flood of SYN packets from many sources. What attack is occurring?
- After a successful phish, a court clerk's mailbox now forwards all mail to an external Gmail address. What continuing attack should the analyst name?
- An attacker uses a stolen help-desk token to reset the utilities-billing administrator. What attack type is this?
- A USB drive left in the library parking lot is plugged into a catalog PC. What is the attack vector?
- A public-facing permits API is abused with SQL-injection-style input. What is the attack vector?
- The water SCADA historian is reachable from the business VLAN because a jump host is dual-homed. What enabling vector should the analyst report?
- During finals week, students rent a botnet and flood the school-grade portal until it is unreachable. How should the analyst describe the attack?
- An insider at the assessor's office copies the property-tax database to a personal cloud drive. What attack type is this?
- A compromised municipal parks-events WordPress page drops a loader on a staff browser. What delivery vector is this?
- Attackers scan a forgotten facilities camera server and find RDP listening on the internet. What is the attack surface?
- A fake city-benefits enrollment site captures logins after staff approve a flood of MFA prompts. What access method is this?
- Malware on a clerk workstation talks to a rare external IP on a high port every 60 seconds. What stage is this pattern?
- A vendor update for the parking-meter backend includes a trojanized installer. What is the attack vector?
- County GIS clients auto-update from a compromised publisher after an email announced the patch. Which named term fits the compromise of that trusted update path?
- Library file servers show mass encryption and a payment note. Which term names this behavior?
- Persistence on a permitting workstation is created with a Windows Run key. In this blueprint, what does registry mean?
- Large night-time uploads leave the health-clinic file share for an unknown S3 bucket. Which term names that activity?
- A city help-desk clerk resets a privileged password after a caller claims to be the CIO and cites an urgent council meeting. Enterprise Security shows no exploit payload, no C2 session, and no stolen token. Which term correctly classifies this attack?
- One angry resident saturates the city's parks-reservation form from a single home IP until the page stops responding. Web logs show no botnet, no distinct source swarm, and no account theft. Which term correctly describes this event?
- The 911 public non-emergency web tip form is overwhelmed by concurrent POST traffic from thousands of distinct source IPs worldwide. Which term correctly describes this attack?
- A single licensing-counter kiosk at the city's DMV-style office is compromised and phones home. Days later, dozens of similar kiosks report to the same controller. How should the analyst label the one host versus the coordinated collection?
- After malware executes on a city clerk workstation, the host opens a periodic encrypted session to an attacker-controlled VPS and waits for instructions. Which term describes that ongoing remote channel?
- The city is adopting zero trust so a finance clerk on the "inside" VLAN is still challenged and granted only the access needed for the job. What does that design actually mean?
- An attacker already has the city treasurer's mailbox password and now enrolls a new MFA method and creates hidden mailbox rules. Which term best describes this stage?
- After a successful phish, a vendor-payment thread is sent from the city comptroller's real mailbox asking a contractor to change the ACH destination. Which term best describes this activity?
- During reconnaissance against the city's 911 CAD, analysts recover a commodity scanner sample. Who or what is the threat actor (adversary) in this incident?
- For months, a stealthy operator uses custom tools against the county elections office, staying quiet and adapting when a host is rebuilt. Which term correctly labels this campaign?
- After a noisy weekend ransomware hit on a library public PC, staff start calling every attacker an "APT." How should the civic SOC correct that mix-up?
- After social engineering produced account takeover of a finance clerk, the actor used the mailbox for email compromise. Splunk now shows large uploads of tax-roll files to an external host. Which blueprint term names the current stage?
- The county board asks whether nation-state actors are targeting U.S. local government this year so it can set budget and risk appetite. Which threat-intelligence tier answers that question?
- An ISAC bulletin describes a campaign expected against U.S. water utilities over the next quarter and lists likely TTPs. Which intelligence tier is that for the city's water SOC?
- Overnight, a feed arrives with IPs, domains, and hashes matching last night's parking-meter malware. What is the right use of that intelligence in Splunk Enterprise Security?
- One bulletin says a crew targeting city halls "uses scheduled tasks and signed binaries for persistence." Another gives a single SHA-256. How should the analyst classify those two pieces?
- The city's threat-intel program loads only file hashes into Enterprise Security. Actors targeting clerk PCs change hashes daily. What should the SOC do?
- An ISAC strategic report says municipal finance systems are a rising target this year. What is the best use of that report inside the city's Enterprise Security program?
- Operational intelligence says a ransomware affiliate is targeting municipal Microsoft 365 this week. What should the city SOC analyst do first?
- Technical intelligence provides a C2 domain used against other city networks. How should the civic SOC operationalize it?
- Using the Pyramid of Pain, how should a city SOC weight a file hash from technical intel versus a tactic from tactical intel?
- A public-health SOC receives strategic, operational, tactical, and technical intelligence in one packet. The night analyst's question is "what do I search for tonight?" Which tier primarily answers that?
- A transit detection engineer attaches MITRE ATT&CK technique IDs to a correlation search. What are those attachments, and why do they matter on Incident Review?
- A court SOC adds ATT&CK annotations to a correlation search that has not matched in months. Staff expect a notable because the annotation is present. What is the correct scope of annotations?
- A risk notable for a city finance user lists annotations from several contributing risk events, each mapping a different ATT&CK technique. What is the intended use of that stacked view?
- A court SOC wants CIS Controls and NIST mappings on the same notables that already show MITRE ATT&CK. What should the defense analyst understand about Enterprise Security annotations?
- After ransomware on a courthouse file server was missed, an analyst wants to stamp last week's notables with a new ATT&CK annotation so the gap looks covered. Why will that not fix the miss?
- A city attorney asks what a courthouse notable actually means. The analyst has the correlation-search SPL and an annotation whose tactic name is Credential Access. Which language should the analyst use in the briefing?
- On a municipal SOC, who usually creates Enterprise Security annotations on a correlation search or risk rule, and who consumes them during triage?
- A wastewater notable is noisy, but its annotation shows ATT&CK Execution. How should the hunter use that annotation next?
- A municipal SOC is documenting an LSASS dump on a finance workstation. How should the analyst label the three TTP layers?
- Two ransomware crews hitting city hall both phish, use valid accounts, then encrypt, but they use different lure text and encryptors. How should the industry regard those TTPs?
- A city SOC inventories only file hashes from a library incident and has no technique IDs. What must it add before it can describe the campaign in the industry's common TTP language?
- A county SOC rewrites detections every time a ransomware encryptor hash changes. What Pyramid of Pain lesson should guide more durable civic detections?
- A transit analyst treats Lockheed Martin Kill Chain "C2" and MITRE ATT&CK "Command and Control" as the same vocabulary. What distinction should the analyst keep?
- After a courthouse intrusion, a civic SOC wants to blog the exact command line its detection used. Why is publishing that procedure-level detail operationally risky?
- An elections hunter writes the hypothesis "the adversary will use T1053 Scheduled Task for persistence on poll-book images." What kind of TTP hypothesis is that?
- A public-health SOC uses Diamond Model capability alongside ATT&CK techniques on the same campaign. What should the analyst conclude?
- A sheriff's office analyst labels every PowerShell event a tactic. What is the correct TTP placement?
- Why does a municipal ISAC share "we saw T1078 Valid Accounts" instead of victim usernames?
Cyber Landscape Frameworks and Standards · 30 questions
- A county SOC manager is filling a night-shift opening. The job poster lists triaging notables on Incident Review, assigning dispositions, and opening investigations. Which SOC role owns that work?
- City water utilities keeps getting noisy correlation searches after a new historian was onboarded. Someone must tune the search, fix CIM mappings, and adjust risk scores. Which role should leadership assign?
- The mayor's office wants a three-year plan for how the municipal SOC will cover MITRE ATT&CK, which data sources to buy, and how Enterprise Security plus SOAR will mature. Which role owns that plan?
- A transit-authority SOC chart shows L1 queue work, L2 deep-dive investigation, L3 hunt and IR surge, plus a separate engineer pod and a CISO-aligned architect. What organization does that chart describe?
- After a library ransomware scare, leadership asks who should write a new "suspicious SMB spike" correlation search and who should work the first notable it creates. How should those duties be split?
- A public-health clinic SOC has one person working the notable queue and also building SOAR playbooks. How should the playbook-build work be classified?
- The county architect publishes a detection-coverage heatmap against ATT&CK and a data-onboarding roadmap. A night-shift analyst treats that as a prompt to redesign CIM mappings before clearing the queue. What is the correct hand-off among the three SOC roles?
- A 911/PSAP SOC runbook says the on-duty analyst may run an ad-hoc Adaptive Response ping from a notable but may not edit that correlation search's scheduled trigger. What does that rule correctly bound?
- Fire/EMS leadership wants someone who can explain to the board why the department bought Enterprise Security and how the program maps to NIST CSF functions. Which role owns that briefing?
- A school-district SOC lists essanalyst versus essadmin style permissions. Which pairing of work to ES capability is correct?
- A city CISO asks how Enterprise Security uses MITRE ATT&CK rather than just hanging a poster on the SOC wall. What is the primary mechanism?
- County detections are tagged to Kill Chain stages so an analyst can see a notable is C2 rather than delivery. How should that tagging be understood?
- A wastewater plant tabletop uses the Diamond Model of adversary, capability, infrastructure, and victim. How should the analyst apply those vertices in Enterprise Security?
- The library director wants the SOC to just block the hashes from a malware sample. Using the Pyramid of Pain, what should the analyst explain about durable detections?
- A municipal compliance officer asks whether Enterprise Security is NIST. What should the analyst say?
- The county wants CIS Critical Security Controls coverage. How do Splunk Security Essentials and Enterprise Security content browsers help the team?
- A transit SOC heatmap in Enterprise Security shows ATT&CK technique coverage from enabled correlation searches. What actually produces that coverage view?
- Public-works leadership calls MFA a framework and MITRE ATT&CK a control. How should the analyst correct that mix-up and place Splunk?
- A court-system SOC enables annotations so a risk notable lists several ATT&CK techniques contributed by different risk events. What is the purpose of those annotations on the risk story?
- The city's cyber-insurance questionnaire asks which standard the SOC follows. How should the analyst treat Splunk in that answer?
- A school district wants zero trust because the term appears in industry blueprints, and a board member asks which Enterprise Security dashboard to open for it. What is the accurate framing?
- Elections staff ask how Splunk incorporates MITRE ATT&CK in day-to-day SOC work rather than in a one-time slide. What is the operational answer?
- A records clerk's laptop is encrypted by ransomware. The county clerk cares that sealed case files can no longer be read. Which information-assurance impact is the clerk describing?
- Someone tampers with wastewater chemical-dose setpoints in the historian, but the pumps still run. Which information-assurance property is hit first?
- A DDoS against the city's permitting portal means residents cannot pull building permits. Which CIA property is primarily affected?
- The library board wants a one-line risk definition the civic SOC can reuse when reviewing malware notables. Which definition should the analyst give?
- The county risk register lists a 911 CAD outage as high impact even though its likelihood is low. How should the analyst use that when prioritizing Enterprise Security detections?
- After identifying phishing risk to municipal email, which set names the basic risk responses the city can choose?
- Asset and Identity marks the elections voter-file server as high priority and a lab PC as low. How should Risk-Based Alerting treat those assets?
- A public-health clinic must protect ePHI confidentiality and keep the after-hours nurse line available. What should the analyst tell leadership about this CIA trade-off?
Defenses, Data Sources, and SIEM Best Practices · 60 questions
- A city SOC already has a perimeter firewall. Leadership asks who connected to the water-plant jump host. Which data source is most useful?
- After suspected malware on a clerk PC, which telemetry best answers which process spawned and which files were written?
- A municipal mailbox may have new forwarding and inbox rules after a suspected email compromise. Which sources should the analyst pull?
- Analysts want to hunt newly registered C2 domains used against city workstations. Where should they look first?
- A secure web gateway sits on staff egress. Leadership asks which clerk visited a phishing lure URL. Why do proxy or Web logs beat raw NetFlow alone?
- A county IDS fires on a library VLAN, and Enterprise Security also shows a notable. How should the analyst treat the two systems?
- A vendor laptop obtained an IP on the library VLAN. Which defense-system logs best explain how that device joined?
- A vulnerability scan shows the utilities portal as exploitable. The analyst still needs to know who logged in last night. What role do the scanner results play?
- The treasurer's SaaS mailbox shows impossible-travel sign-ins. Which source is most useful for that account-takeover analysis?
- Leadership asks who changed the S3 bucket policy on the municipal data lake. Which telemetry answers that control-plane question?
- A county SOC believes an attacker is hopping from a clerk workstation onto file shares with stolen domain credentials rather than new malware. Which data source is most useful for confirming lateral movement via valid accounts?
- A city firewall shows 10.20.30.40 contacting a rare destination at 02:00, and the SOC must name the laptop and the staff identity that held that address. What should the analyst combine?
- A transit edge firewall's syslog reports a blocked session but has already dropped the protocol fields the analyst needs. Which analysis tool should the analyst use next?
- The city SOC matches a quarantined file hash to an Enterprise Security threat list. Unless a blocking control is also in the path, what does that match provide?
- A clerk mailbox may have sent a large archive off-network, and the wastewater plant reported a PLC setpoint change in the same hour. Which source is useful for the data-leaving question and should not be first for the PLC change?
- Investigators need to know whether the night operator was physically inside the water plant when a suspicious workstation logon occurred. What can physical badge logs provide?
- A county just deployed a SOAR platform next to Enterprise Security. The first hunt for unusual treasurer-account logons still needs a primary data source. What should the analyst pick?
- A wastewater-process question is whether anyone used the jump host and then changed a pump setpoint through the industrial firewall. Which sources are useful?
- The city mail gateway quarantined an unknown attachment on a permitting clerk's message. Which analysis tool should the SOC use to learn what the file does?
- During one city incident, the IR lead asks who logged in as the treasurer, what that account resolved in DNS, and what binary ran on the workstation. How should the analyst pick the most useful data sources?
- County edge traffic is split across two firewall vendors that name source and destination fields differently. How should an Enterprise Security analyst write one investigation search that covers both?
- A clerk-login failure on the treasurer workstation needs a CIM data-model search. Which data model should the analyst use?
- The SOC needs a fast count of failed logons for the treasurer account across last week. Which SIEM search approach is the best practice in Enterprise Security?
- An analyst's tstats search on the Authentication data model returns no failed logons for the county DC, but raw WinEventLog:Security events exist. What should the analyst check before blaming the domain controller?
- Enterprise Security is installed, but the Access and Network domain dashboards stay empty even though firewall and Windows logs are indexed. What is missing?
- A wastewater historian should raise urgency when it appears on a notable. What does the Asset and Identity framework add so that happens?
- Enterprise Security still creates notables on a county file server, but owner, priority, and urgency look blank or wrong. What should the analyst diagnose?
- A civic workstation's DHCP hostname does not match its DNS name, and Asset and Identity never attaches owner or priority to the notable. Which keys does A&I use to join events to assets?
- A municipal mail-relay event is CIM-mapped with user, srcuser, and destuser populated. The question under investigation is which clerk identity sent the message through the relay. Which field should the analyst filter on?
- A city analyst searching NetworkTraffic filters src to the edge firewall hostname and no client sessions appear. What was confused?
- Help desk tells the SOC the city was breached because an IDS signature fired toward the elections file server. Which CIM field should the analyst check first before escalating?
- The county EDR may have seen a malware family on a clerk PC. Which CIM fields on the Malware data model answer that, rather than url?
- A parks-site watering-hole visit is the investigative question. Which CIM fields, on which data model, should the analyst use?
- A transit analyst sees rare egress from a station kiosk and needs to know whether it was HTTPS or a raw high-port beacon. Which CIM fields characterize that egress?
- Both the civic firewall and the EDR wrote overlapping events for the same clerk workstation. How should the analyst tell which product produced a given event?
- A city SOC wants one brute-force correlation to cover both the Palo Alto and Cisco ASA in front of the permitting portal. Analysts still paste vendor field names into every search. What is the SIEM best-practice next step?
- A county IR lead hunts a wastewater-plant login from two minutes ago. A tstats search on the accelerated Authentication data model is empty, but raw WinEventLog:Security shows the event. What should the analyst conclude?
- A city analyst is drafting an Enterprise Security correlation search for after-hours admin logons on court case-management servers. Which dataset should that search use?
- A terminated assessor clerk still shows as active staff on notables because the identity lookup last refreshed before HR finished offboarding. What SIEM problem is that?
- The elections file server is marked critical in the Asset lookup. A malware notable fires on that host. How should urgency be handled?
- A parks notable names a seasonal intern's user and a kiosk src. What is the CIM-correct way to see that intern's logons, then egress, then browsing?
- The city onboarded a new school-district web proxy. Raw events appear in Search, but the Enterprise Security Web Security Domain dashboard stays empty. What should the analyst diagnose?
- A county just started sending WinEventLog:Security from the sheriff records LAN. How should the analyst find which detections that sourcetype unlocks?
- The city wants AWS CloudTrail detections for the permitting buckets. Splunk Security Essentials and Enterprise Security content search show those detections require a CloudTrail sourcetype that is not onboarded. What should the analyst tell the team?
- A civic domain controller serving the courts OU is seeing a burst of failed logons. Which on-prem sourcetype should hold the brute-force evidence?
- The treasurer's Microsoft Entra ID account shows a sign-in from an unfamiliar country. Which cloud sourcetype should the analyst pull first?
- A small city's Splunk Security Essentials data-source checklist shows rich firewall syslog but no DNS. Command-and-control content is marked weak. What should the analyst conclude?
- The library consortium's Enterprise Security Web domain dashboard is empty, while the Access domain shows staff logons. What is the most likely data-source assessment?
- Transit edge devices now send pan:threat. How should analysts find official detections and dashboards for that sourcetype?
- The housing authority has an on-prem domain controller plus Entra ID for cloud apps. A privileged-logon hunt used only Entra content. What did the hunt miss?
- Wastewater historians send a custom OT sourcetype. Splunk Security Essentials shows no matching content. What is the right next step?
- Windows security was onboarded as the custom sourcetype citywinsec instead of WinEventLog:Security. Security Essentials content keyed on the standard name shows nothing. Why?
- The city council wants a statement that ransomware detections are live. What should the analyst do first?
- Someone created an IAM user and attached AdministratorAccess in the city's AWS account. Which sourcetype holds that API evidence?
- A clerk's mailbox grew a hidden forwarding rule. Separately, the SOC needs the path of one phishing message through Exchange Online. Which sourcetype split is correct?
- A library just onboarded Sysmon. Where should the analyst look first for process-creation and DNS-query detections already written for that sourcetype?
- While looking for content tied to a new court-camera NVR sourcetype, a junior analyst only searches for a saved search whose name matches the sourcetype. What else should they include?
- Splunk Security Essentials shows the city has Cisco ASA events, but CIM NetworkTraffic fields are empty. What pair of actions is the best-practice path?
- Public health's cloud EHR is SaaS and has no Splunk-supported ehr:cim sourcetype. How should the analyst assess useful data?
- The housing authority wants a documented check that account-takeover content is actually usable. What is the correct sequence?
SPL and Efficient Searching · 60 questions
- A county SOC needs a 24-hour count of failed civic VPN logons by user. The Authentication data model is accelerated. Which SPL family should the analyst use?
- The city just onboarded a new PSAP CAD sourcetype. An analyst runs tstats on the Authentication data model and sees none of the new events. Why?
- A huge county index would be too expensive if tstats fell back to raw events. The analyst only wants summary data. What should they set?
- After a tstats count of the treasurer's failed logons, the analyst needs a trend table by hour. What is the next SPL step?
- An analyst must reconstruct a clerk session: civic VPN logon, then file-share access, then rare egress. The events share user and occur within a bounded pause. Which command should glue them into one session?
- The analyst only needs each user's first civic VPN time and last file-share access, not a full multi-event session. Why is stats first() last() better than transaction?
- An analyst is investigating a comptroller mailbox-rule creation followed by the first outbound BEC-style send. How should transaction be bounded?
- A help-desk account shows a burst of failed civic logons and later a success. Which SPL pair shows whether brute force later succeeded?
- A suspect IP is talking to civic hosts in NetworkTraffic. The analyst needs the most recent dest that src reached, without building a full transaction. What should they use?
- To estimate dwell on a utilities risk object, the analyst needs when activity began. What timestamp should they take from the contributing events?
- A custom parking-meter syslog buries the meter ID in the raw message. The analyst needs that ID as a field for later stats. Which command extracts it in the search?
- The parking-meter ID extraction will be needed every night, not just this incident. When should the analyst stay with search-time rex versus a durable extraction?
- A parks watering-hole URL is already in the CIM url field. The analyst needs the second-level domain. How should they run rex?
- A clinic file-share investigation has mixed action values (allow versus allowed) and needs a flag when bytesout exceeds 100000000. Which command calculates those analysis fields?
- During an ad-hoc hunt, the analyst has civic failed-logon counts per user and wants low, med, and high buckets. Which eval form classifies those results?
- A public-health clinic EDR stores file hashes in uppercase, but the county ISAC intel lookup table is lowercase, so known malware hashes return no matches. What should the analyst do before the lookup?
- Wastewater SCADA events include srcip, destip, and c2ip. The analyst wants to flag which of those addresses are RFC1918 without writing three nearly identical eval statements. Which SPL approach fits?
- A library catalog-PC malware event exposes several hash fields named filehash, filehashmd5, and filehashsha256. How can the analyst lowercase every filehash field in one pass for intel matching?
- During incident response on a city workstation, the analyst has src but needs the asset owner, priority, and business unit from the municipal asset table — the same context Asset and Identity would add in Enterprise Security. Which SPL command should they use?
- A transit SOC analyst has a rare destination domain and a file hash from last night's parking-meter malware. What is the right way to see whether those values appear on the ISAC indicator list already loaded as a lookup?
- A court-system notable already has a CIM user field. The analyst runs a sparse HR lookup that only matches some clerks. Which lookup writing option preserves the original user on non-matches instead of wiping it?
- A school-district analyst needs to prove a new parent-portal user lookup returns the expected department before the next phishing wave. There is no live attack to search. Which command creates a dummy row so the lookup can be tested?
- Housing-authority engineers added a ransomware-hash intel table. The analyst must confirm lookups hit before any correlation search uses that table in production. How can they test it without querying live indexes?
- The elections office wants failed logons on high-priority voter-file hosts investigated first. Which SPL sequence best prioritizes that hunt?
- A sheriff's-office help-desk ticket mentions a password reset after a caller impersonated a captain. The ticket ID sits only in the raw help-desk message, and the reset event follows. How should the analyst reconstruct where the reset came from?
- A parks-department intern runs makeresults expecting to see last night's irrigation-controller syslog. The search returns one empty-looking row and no device logs. What is the correct explanation?
- A permitting-office analyst needs to attach DHCP hostnames to firewall src addresses. A teammate suggests using rex to join the two datasets. What should the analyst do instead?
- A fire/EMS analyst maps SPL jobs to commands: aggregate accelerated models, glue a time-bounded session, extract a buried field, calculate a flag, enrich from a table, or test without indexes. They need to enrich a rare dest IP with station owner and priority from the municipal asset CSV. Which command matches that job?
- A 911/PSAP CAD outage started in the last hour. An analyst's first investigation search uses All Time on the CAD index. What is the most important efficient-search fix?
- A city SOC is hunting last hour's firewall denies for the tax portal. Which initial filter follows Splunk efficient-search practice?
- A sheriff's-office analyst searches high-volume authentication logs with admin to find privileged civic accounts. Why is that pattern a problem?
- County Windows failed-logon volume is huge, and the Authentication data model is healthy and accelerated. What is the efficient default for counting EventCode 4625-style failures?
- After filtering assessor-office authentication events, later commands only need src, user, and action. How should the analyst reduce search cost?
- A municipal hunt is streaming every clerk-PC endpoint event into the search UI before anyone counts users. What efficient-search change should come first?
- A city hunt for hosts that talked to C2 uses a subsearch that returns an entire day's destination IPs and then hits subsearch limits. What should the analyst do instead?
- An analyst runs transaction across a week of proxy logs for every city employee to find rare destinations. Why is that an efficiency anti-pattern, and what is the better pattern?
- A wastewater hunt already knows the CIM fields it needs and can use tstats on a healthy model. The analyst leaves the search in verbose mode on huge indexes. What should they change?
- Transit bus-CAD events already have a CIM src field from the add-on. An analyst still runs rex on millions of hot events to extract the same source address. What is the efficient practice?
- A library malware hunt looks for a rare mutex string. The analyst uses a loose substring with wildcards and the search scans far more events than expected. What is the efficient way to seek that indicator?
- A county IR hunt and a heavy weekly compliance report are competing with 911 monitoring searches on the shared search head. What efficient-search courtesy should the analyst apply?
- A city SOC analyst needs a running count of failed VPN logons per clerk identity for the last hour, but the draft search starts with index= | streamstats count by user. What should the analyst change first?
- Transit SOC needs the top talkers on the bus-yard network for the last 15 minutes, and an intern starts exporting raw NetFlow events to Excel. What should the analyst do instead?
- The mayor's office dashboard of 911 SIP error counts refreshes every five minutes and currently runs a raw index search on each refresh. What should the city SOC recommend?
- A PSAP dashboard counts 911 SIP errors in one-minute buckets, and the current minute always looks artificially low while events are still arriving. What should the analyst change?
- Water-plant SOC already knows the jump-host name for a hunt, but the draft search filters only on a search-time field after scanning the whole index. What should the analyst add to the first clause?
- A county hunt for unusual library-kiosk logons is slow because the search runs a lookup and several eval transforms before any index filter. Which order should the analyst apply?
- A new courts-SOC analyst thinks reusable security SPL exists only in the Search app. Where else in Enterprise Security should they look?
- A sheriff-jail SOC analyst has a new case that looks like last week's notable. What is a legitimate way to start the investigation SPL?
- A city endpoint team just onboarded Sysmon and asks the SOC for hunts that actually use that sourcetype. Where should the analyst look first?
- A county analyst found a relevant use case in Splunk Security Essentials but is about to write new regex for the same behavior. What should they do instead?
- The public-health SOC needs an official Splunk how-to for investigating ransomware, including example searches. Which resource is that library?
- A wastewater analyst is about to write a brand-new search for historian setpoint changes. What should they do first?
- A parks-department SOC lead needs analysts to keep Enterprise Security, Splunk Security Essentials, and Splunk Lantern straight. Which assignment is correct?
- An elections-SOC intern bookmarks a random blog of secret SPL dumps as the team's search library. Which sources should the analyst treat as the Domain 5.3 SPL libraries instead?
- The ES Network Security Domain dashboard for the fire and EMS network is empty. Which SPL-adjacent resource should the analyst use to learn why the search has nothing to run on?
- Housing-authority SOC is investigating suspected ransomware on file servers. How should the analyst use a Splunk Lantern ransomware-investigation article?
- A permitting-desk analyst rewrites CIM Authentication filters by hand because using ES-shipped macros feels like cheating. What should the lead tell them?
- Library SOC bookmarked a high-value hunt in Splunk Security Essentials and wants it to become an ES detection. What should the analyst know about that path?
- Library SOC is onboarding a junior analyst. Which enablement pack should the lead hand them first?
- A vendor gist contradicts Enterprise Security, Splunk Security Essentials, Splunk Lantern, and Splunk Docs on how a civic Authentication search should be written. What is the source of truth?
Investigation, Event Handling, Correlation, and Risk · 60 questions
- A city SOC manager treats continuous monitoring as the quarterly audit spreadsheet of civic systems reviewed last quarter. What should the defense analyst explain instead?
- A clerk workstation is ticketed as slow, and a matching notable is already in the Analyst Queue. The night analyst starts by wiping the PC. What should have been the first of Splunk's five investigation stages?
- After identifying a notable on a county permitting host, the analyst's next move is to reimage every PC in the department. Which Splunk investigation stage should come next instead?
- A county SOC has scoped a treasurer-account notable to one user and a four-hour window. Leadership wants the account disabled before anyone looks at contributing events. What belongs in Splunk's third investigation stage first?
- Analysis confirmed a treasurer identity used a public kiosk to reach a listed command-and-control host. When should the analyst disable the account, block that host, or isolate the kiosk?
- A library catalog incident is contained. The city wants to close the case and skip everything after remediation. Which work belongs in Splunk's fifth investigation stage?
- A night-shift analyst sees a 911 CAD notable and immediately pulls the CAD network interface to contain it, skipping analysis. What is wrong with that sequence?
- A city manager lists Splunk's five investigation stages and puts continuous monitoring as stage one. How should the analyst correct that mix-up?
- An analyst moves a parks notable from New to In Progress to Resolved and tells the shift lead those statuses are Splunk's five investigation stages. What should the lead clarify?
- After a permitting-portal incident, the city restored service, documented the case, and closed the notable. What should the SOC still confirm about continuous monitoring?
- County leadership asks for dwell time on last week's finance incident. An analyst reports the 40 minutes the notable was assigned. What is dwell time?
- A city CIO funds more unused Enterprise Security dashboards and claims mean time to detect will drop. What does MTTD actually measure?
- The municipal SOC defines MTTR as starting at detection and ending when the threat is contained. A parks kiosk sat undetected for six days and was then isolated in 45 minutes. Which statement about MTTR is correct?
- Leadership wants lower dwell on the county network and proposes buying more wall screens for the SOC. What actually moves dwell?
- A city SOC brags about a 20-minute MTTR while attackers remain on the water SCADA jump host for two weeks before anyone notices. What trap should the metrics review expose?
- A transit SOC scoreboard ranks analysts by tickets closed per hour, and dispositions are being rubber-stamped. What should analysts help the city define instead?
- The county wants time-in-status numbers that feed MTTR. An IT manager orders a new ITSM tool because Splunk cannot time a notable. Where should the municipal SOC measure that?
- Leadership wants one county-wide MTTR target for both 911 CAD and a library kiosk. How should the analyst set expectations?
- An EDR notable fires on a city software-packaging tool that IT already approved for clerk image builds. The analytic matched real packaging behavior. Which disposition should the analyst assign?
- A correlation search treats every municipal syslog line as a failed logon because a technical add-on maps the wrong field. Which disposition fits?
- Yesterday's infected DHCP address now belongs to the mayor's laptop, and a malware notable names that laptop. The lease was reused after the infected host left. Which disposition is correct?
- Investigation confirms credential stuffing against the utilities payment portal that the city did not authorize. Which disposition should the analyst assign?
- Night shift has not finished scoping a wastewater-plant notable. A supervisor wants it labeled True Positive so the queue looks clear at dawn. What should the analyst do?
- An elections-office notable is confirmed malicious, but containment is still underway. A clerk sets status to Resolved, thinking that means False Positive. What should the analyst keep separate?
- A civic analyst correctly assigns False Positive - Incorrect Analytic Logic to a noisy parks notable and then ends the shift. What is still required?
- A county SOC sees two port-scan notables after the same night: one source is the city's authorized vulnerability scanner during the published window, and the other is an unknown external host. How should the analyst disposition them?
- A wastewater SOC analyst is told to use SPL against civic indexes and the Authentication data model while scoping a notable. What is SPL in that workflow?
- A 911 PSAP analyst has a red syslog line in Search and a tracked item on Analyst Queue after a correlation search ran. Which object is the Notable Event they triage?
- The county treasurer account collected several cheap risk events—rare VPN, a new mailbox rule, off-hours admin—without paging the on-call. A queue item appears only after the aggregated score crosses the city's threshold. What fired?
- A risk notable for suspicious activity around the county treasurer shows a rising score. Which entity is the Risk Object that holds that score?
- A risk notable fired on the treasurer identity. The analyst needs to explain why the score exists before briefing finance. What should they expand?
- A library SOC analyst needs to run ping or send a notable to SOAR from a correlation search or from an open notable. Which ES construct is that action framework?
- A transit analyst says notables and Adaptive Response are mutually exclusive, so a correlation search that creates a notable is not using AR. What is the correct relationship?
- The municipal VPN detection for a logon from a rare city is too cheap to page the on-call by itself. How should that hit become part of a later risk notable?
- A clerk-account risk notable is in the city queue. What is the intended sequence using the notable, contributing events, and SPL together?
- A fire/EMS analyst finds a concerning firewall deny in Search that no correlation search has tracked. Is that event a notable?
- An elections risk story shows scores on both the elections clerk (user) and the elections workstation (system). How should the analyst treat those risk objects?
- From a courts notable, the analyst runs ad-hoc ping and nslookup. What job do those Adaptive Response actions do compared with a risk notable?
- The city SOC needs the built-in queue of notables and findings with title, urgency, owner, status, disposition, and time. Which dashboard is that?
- County leadership asks the analyst to close civic tickets from the Risk Analysis dashboard. What is that dashboard actually for?
- The CIO wants a civic-wide snapshot of notables by domain and urgency for the morning briefing, not a packet decode. Which built-in ES view fits?
- A municipal-accounts investigation needs authentication patterns, rare logons, and access anomalies. Which ES dashboard family should the analyst open first?
- The city needs malware and process context on clerk workstations, then firewall and IDS context on the same incident. Which Security Domain dashboards match those telemetry types?
- Clerks are hitting a fake benefits-enrollment site. The analyst needs URLs, categories, and proxy users. Which ES dashboard family is the right place?
- The SOC must assemble one permitting clerk's activity across sources instead of bouncing between five raw searches. Which ES capability is built for that?
- A housing-authority account shows logons at improbable hours from an unusual geography and a sudden volume spike. The lead says it might be a DDoS dashboard problem. Which ES view is actually built for that access pattern?
- The county wants protocol-level DNS and HTTP context on civic hosts. When will Protocol Intelligence / stream dashboards actually show that data?
- Leadership asks two questions: which civic hosts talked to a listed C2, and how analysts handled the resulting notables. Which dashboard pairing answers those?
- The city SOC still pages the on-call for every cheap signal—rare VPN, new mailbox rule, off-hours admin on the treasurer account. What RBA change should they make?
- A civic engineer asks the analyst what an Enterprise Security correlation search actually is before they request a new detection. Which definition should the analyst use?
- A county SOC is adding a correlation search for a weak civic signal: a treasurer VPN from a rare city. Leadership wants fewer single-signal pages to on-call. How should that search's adaptive responses be designed?
- A city finance clerk and a wastewater historian both need scores from new RBA content. How should the risk objects be typed?
- A municipal SOC is creating several weak risk rules for parks, courts, and permitting accounts. What should each rule include so a later risk notable automatically tells an ATT&CK story?
- The city set the risk-notable threshold so low that Incident Review looks like the old one-alert-per-signal queue. What RBA adjustment should the SOC make first?
- A correlation search for wastewater firewall denies is flooding notables because one noisy historian produces hundreds of matching rows. What should be configured on the search so adaptive responses do not fire on every row?
- Nightly authorized vulnerability scans of the library catalog keep creating the same notables. The search logic is correct. What should the analyst use so those known-benign items leave the working queue without deleting history?
- A county analyst finds an elections clerk mailbox-forwarding pattern that no correlation search turned into a notable. What Enterprise Security action should the analyst take so the event is tracked in the queue?
- Leadership wants the county elections file server to start with a higher baseline risk than a library kiosk. How should that adjustment be made?
- The CIO asks why a utilities clerk now has a risk notable. What must the civic RBA stack provide so the analyst can explain the notable without guessing?
- A city analyst must request a new correlation search for permitting-portal account-takeover signals. What understanding is enough for that request without becoming the Enterprise Security administrator?
Threat Hunting and Remediation · 30 questions
- Water-plant hunt finds no known malware hashes on jump hosts, and the hypothesis is that someone disabled logging or added a local admin. Which hunting technique is this?
- County SOC wants to hunt clerk VPN days that do not look like a normal 9-to-5 workweek. Which technique fits?
- The state ISAC publishes a C2 domain tied to a campaign against municipal email. What hunting technique should the city SOC run first against Web, DNS, and firewall data?
- An elections clerk identity that never touched the elections file server suddenly accessed it and then created a mailbox forwarding rule. Which hunt technique describes that sequence?
- City SOC has three open hunts: an unknown actor on the assessor network, a known campaign with ISAC IoCs, and a question of whether someone turned off Sysmon on a jump host. How should the analyst match techniques?
- County Asset and Identity records mark wastewater jump hosts as shouldupdate, but endpoint telemetry has not reported a patch cycle in 45 days. What hunt technique should the civic SOC apply first?
- Anomaly modeling flags a twenty-times spike in city website bandwidth every election night and during council livestreams. What should the hunter add to the model?
- A behavioral hunt finds several odd but individually weak actions on a permitting clerk identity. How should those findings feed Enterprise Security?
- The city proxy shows millions of visits to common sites and a handful of one-hit destination domains. What does long-tail analysis tell the hunter to inspect first?
- A hunter ranks municipal users by destination-port frequency and finds one clerk with a single connection to destport 4444. What long-tail approach does this illustrate?
- Failed logons against a county domain controller jump to three standard deviations above that DC's own baseline, and no threat-intel hash is present. What technique is the hunter using?
- A wastewater historian host writes ten times its normal volume to disk, but no known malware hash is present. What should the civic SOC do?
- The city SOC wants to hunt whether a valid finance account will create an inbox forwarding rule and then exfiltrate via personal cloud. What is the correct hypothesis-hunting sequence in Splunk?
- A junior hunter proposes the hypothesis that hackers are here on the elections network. What change makes it a testable Splunk hunt hypothesis?
- A hunt for new forwarding rules on city finance mailboxes returns no matches this week. What should the analyst do with that outcome?
- A hunt confirms rare destport 4444 egress from library kiosks. How should the civic SOC turn that success into continuous monitoring?
- Which Adaptive Response usage is appropriate for the city SOC?
- An analyst opens a notable for a parks workstation and wants Adaptive Response during the analyze stage. Which ad-hoc use is appropriate first?
- The same pair of actions—create a notable and add risk—should fire every time a parking-garage camera detection matches. How should Adaptive Response be configured?
- A hunter needs each true match on a court-clerk detection to raise the identity's risk score without paging email. Which default-style Adaptive Response should be selected?
- A correlation search emails the on-call analyst for every parking-meter result, and 5,000 meters flap overnight. What Adaptive Response configuration change is needed?
- On a fire-station notable, the Adaptive Response icon never shows success. What should the analyst check first?
- A notable fires on the city's 911 CAD server. Why is automatic isolation Adaptive Response usually the wrong next step?
- A new analyst asks what a SOAR playbook is in the city's defense stack. What is the accurate description?
- How can a scheduled detection automatically start SOAR work from Enterprise Security?
- A county analyst wants a playbook to run for one parks notable without changing the correlation search. What Enterprise Security trigger path should they use?
- While working an elections investigation in Enterprise Security, the analyst needs to launch playbook actions as part of the case workflow. Which trigger path does this describe?
- Leadership asks the civic SOC analyst to write the Python for a new SOAR playbook after a library kiosk incident. What is in scope for the Cybersecurity Defense Analyst?
- Which SOAR trigger policy fits the city's risk tolerance?
- A true-positive notable never appears in Splunk SOAR. Where should the civic SOC troubleshoot first?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by Splunk.