Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

SPLK-5002 Splunk Certified Cybersecurity Defense Engineer Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Splunk SPLK-5002 Splunk Certified Cybersecurity Defense Engineer certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 105 questions

Which of the following cURL commands would allow an engineer to effectively disable the REST API endpoint they ' ve been utilizing for testing a detection named TestSearchDevelopment?

A.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/ -X DELETE

B.

Splunk endpoints cannot be disabled.

C.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X POST

D.

curl -k -u admin\:pass https://localhost:8089/servicesNS/admin/search/saved/searches/TestSearchDevelopment/disable -X PUT

Which of the following detections would use a high count of events with Windows Event Code 4740 grouped by a user to determine suspicious behavior?

A.

Detect Excessive AWS Security Scanning

B.

Detect Excessive User Account Lockouts

C.

Detect Excessive User Logins

D.

Detect Excessive Network Connections

When developing security metrics, why would a Key Performance Indicator (KPI) that focuses on total perimeter firewall blocks be an ineffective metric?

A.

This a Key Result Indicator, not a KPI. It is a metric that is measuring the results of the perimeter firewall ' s actions, not the performance of the firewall.

B.

Perimeter firewalls are exposed on the internet directly and thus subject to automated scanners and attack tools.

C.

The metric is too high level, it should be broken down by the type of block. For example, blocks of remote systems that have repeated failed connections to services that do not exist.

D.

Perimeter firewalls should be measured on both the number of connections that they permit as well as the number they block.

During a ransomware attack, an adversary might add a default user and password in registry, modify the wallpaper, and create bulk ransomware notes across multiple machines. What is Splunk ' s method for grouping these types of detections together?

A.

Threat Intelligence

B.

Data models

C.

Analytic Stories

D.

Assets & Identities framework

There are multiple methods for communicating data with a REST endpoint. In the URL shown, what is the name of the key-value pairs represented after the question mark in the URL?

A.

Parameters

B.

Payload

C.

Headers

D.

KV Elements

Which stats event field created by an adaptive response action allows for troubleshooting the correlation search that created the notable event?

A.

orig_sid

B.

risk_sid

C.

search_sid

D.

result_sid

MITRE D3FEND® is designed to complement MITRE ' s list of adversarial tactics, techniques, and common knowledge (ATT & CK). Which tactics are associated with MITRE D3FEND in order to detect, deny, and disrupt adversarial efforts?

A.

Harden, Detect, Isolate, Disrupt, Evict

B.

Harden, Detect, Enrich, Define, Eradicate

C.

Harden, Detect, Isolate, Deceive, Evict

D.

Harden, Detect, Exhaust, Deceive, Eradicate

What does the following search do?

source=WinEventLog:security* sourcetype= " WinEventLog* " EventCode=4688

| stats count, values(process) as process by parent_process_name

A.

Displays a count of processes created by the same user.

B.

Displays a list of newly created processes and the user that created them.

C.

Displays a count of processes created by the same child process.

D.

Displays a list of processes and their parent processes.

What field is used by default to direct data into CIM data model datasets?

A.

tag

B.

sourcetype

C.

source

D.

dataset

In Enterprise Security, what is the name of the threat intelligence lookup pertaining to files?

A.

file_hash

B.

file_intel

C.

user_intel

D.

user_hash

Based on a recent red team exercise, an organization is highly concerned about pass-the-hash attacks, especially including tools like Empire. Which EventCode associated with PowerShell Script Block Logging would be used to detect this activity?

A.

EventCode=4104

B.

EventCode=4126

C.

EventCode=4624

D.

EventCode=4168

Which action improves the effectiveness of notable events in Enterprise Security?

A.

Limiting the search scope to one index

B.

Using only raw log data in searches

C.

Applying suppression rules for false positives

D.

Disabling scheduled searches

Which REST call will show a list of alerts with their specific commands, app, and title?

A.

| rest /servicesNS/admin/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

B.

| rest /servicesNS/user/-/alerts/alert_actions

| table title, eai:acl.app, label, payload_format, command

C.

| rest /servicesNs/admin/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

D.

| rest /servicesNS/user/-/actions/alert_actions

| table title, eai:acl.app, label, payload_format, command

Which of the following is the most efficient search to return a list of all visible indexes and the sourcetypes contained within them?

A.

A raw-event search followed by aggregation.

B.

A non-index-grouped metadata search.

C.

An index=* event search followed by stats.

D.

A tstats search returning sourcetypes and grouping them by index.

In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

A.

service_intel

B.

http_intel

C.

certificate_intel

D.

ip_intel

When creating a detection that searches user activity across CIM-compliant data, which CIM field should be reviewed to ensure that data is aggregated appropriately?

A.

user_id

B.

user

C.

action

D.

identity

Which of the following is a reason to utilize ES risk framework as a part of detection building?

A.

Help accelerate the run time of detections, allowing a faster mean time to detection.

B.

Create a feedback loop into threat intelligence to identify potential insider threats.

C.

Help prioritize security findings based on their potential business impact.

D.

Simplify SOAR automation and remediation, lowering the mean time to recover.

The SOC notices over the course of an investigation there are numerous logs similar to the following:

UDP: query: reallybad.c2.com IN A response: SERVFAIL

What detection should be created to alert on this behavior for the future?

A.

Excessive DNS Failures

B.

Excessive Authentication Failures

C.

Excessive Network Failures

D.

Excessive Endpoint Failures

In a Risk-Based Alerting implementation with Splunk Enterprise Security, which of the following best describes a risk factor?

A.

A multiplier of risk that depends on the characteristics of the specific user or asset.

B.

An event that modifies risk based on the characteristics of the specific user or asset.

C.

A tool to enable risk data model acceleration.

D.

A SOAR action that is drawn from annotations.

Which of the following should be the primary reference when designing a new playbook in Splunk SOAR?

A.

Existing investigation actions

B.

MITRE ATT & CK® framework

C.

Existing Standard Operating Procedure

D.

CIS Framework

Page: 1 / 2
Total 105 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved