SPLK-5002 Sample Questions & Answers
Creating and refining correlation searches as detections, with risk-based modifiers, carries by far the most weight, next to data normalization, developing threat intelligence, automating response through REST APIs, and reporting on security metrics.
Launch the full SPLK-5002 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Automation and Efficiency · Compare ES and SOAR automation capabilities
When integrating Splunk Enterprise Security (ES) with Splunk SOAR, an administrator wants to ensure that when a Notable Event's status is changed to 'Closed' in ES, the corresponding container in SOAR is also closed automatically.
Which feature must be configured to enable this synchronization?
Show answer & explanation
Correct answer: B
The Splunk App for SOAR Export (or Phantom App) configured on the search head allows for bidirectional synchronization. This ensures that status changes in ES notables are reflected in SOAR containers, and vice versa.
- Question 2Intermediate
Detection Engineering · Create and tune detections
A detection engineer is reviewing the efficacy of a specific correlation search. They notice that the search generates a high volume of alerts for a specific administrative subnet (10.10.5.0/24) performing legitimate scanning activities.
What is the most effective way to suppress these specific alerts without disabling the detection for the rest of the network?
Show answer & explanation
Correct answer: B
Using a managed lookup for whitelisting is the best practice. It separates the detection logic from the exclusion data, making it easier to maintain and audit changes to the whitelist without editing the core SPL of the correlation search.
- Question 3Beginner
Detection Engineering · Incorporate context into detections
True or False: In Splunk Enterprise Security, the Asset and Identity frameworks can automatically enrich notable events with departmental information, but they cannot effectively prioritize alerts based on the 'criticality' field of an asset.
Show answer & explanation
Correct answer: B
This is False. The Asset and Identity frameworks are explicitly designed to prioritize alerts. By defining the 'priority' or 'criticality' category for assets (e.g., PCI servers, C-level laptops), ES can calculate a higher urgency for Notable Events involving those assets.
- Question 4Beginner
Auditing and Reporting on Security Programs · Develop and optimize security metrics
A security manager requires a monthly report detailing the 'Mean Time to Detect' (MTTD) and 'Mean Time to Respond' (MTTR) for the SOC.
Which Splunk Enterprise Security dashboard provides these metrics out-of-the-box?
Show answer & explanation
Correct answer: A
The SOC Operations dashboard (sometimes labeled Incident Review Operations in newer versions) specifically tracks the efficiency of the SOC, including key performance indicators like MTTD, MTTR, and investigations per analyst.
- Question 5Intermediate
Detection Engineering · Create and tune detections
You are creating a new correlation search to detect 'Brute Force Access' attempts. You want to ensure that if the search runs every 5 minutes and detects an attack, it creates a Notable Event, but does NOT create another duplicate event for the same user and destination for at least 1 hour.
Which configuration setting handles this requirement?
Show answer & explanation
Correct answer: A
Window Throttling (configured in the correlation search editor) allows you to suppress subsequent alerts based on a set of fields (e.g., user, dest) for a specified duration (e.g., 1 hour), preventing alert fatigue.
- Question 6Advanced
Building Effective Security Processes and Programs · Research, incorporate and develop threat intelligence
Case Study: GlobalFinance Corp
GlobalFinance Corp has a distributed Splunk environment. They are implementing a Threat Intelligence program. They have three requirements:
- Ingest a paid STIX/TAXII feed from 'VendorX'.
- Automatically verify if any internal IP addresses have communicated with malicious IPs from this feed in the last 24 hours.
- If a match is found, raise a 'Critical' Notable Event.
The engineer has configured the Threat Intelligence Download in Enterprise Security to fetch the feed.
What is the next logical step to automate the detection of historical matches (Requirement 2)?
Show answer & explanation
Correct answer: C
Splunk Enterprise Security includes default correlation searches like 'Threat - Threat List Activity - Rule' that automatically compare incoming events (or data model summaries) against the threat intelligence collections. Enabling and tuning this rule satisfies the requirement to detect matches.
- Question 7Intermediate
Detection Engineering · Create and tune detections
When mapping a detection to the MITRE ATT&CK framework within Splunk Enterprise Security, which field is primarily used to link the correlation search to a specific Technique ID (e.g., T1059)?
Show answer & explanation
Correct answer: A
In modern Splunk ES versions, the 'Annotations' framework is used. You add an annotation with the name 'mitre_attack' and the value as the Technique ID (e.g., T1059).
- Question 8Intermediate
Automation and Efficiency · Automate responses using SOAR playbooks
A SOC team wants to automate the 'Containment' phase of their Incident Response SOP. They decide to use a Splunk SOAR playbook.
Which of the following describes the correct order of operations for a robust containment playbook?
Show answer & explanation
Correct answer: B
A robust containment workflow should always include a human-in-the-loop (Prompt) to avoid accidental outages, followed by the action execution, and crucially, a verification step to ensure the action worked before updating the ticket.
- Question 9Beginner
Building Effective Security Processes and Programs · Optimize Case Management
What is the primary function of the 'Notable Event Status' transition in the Incident Review dashboard?
Show answer & explanation
Correct answer: D
Status transitions are the core mechanism for tracking investigation progress. They allow the SOC to understand workload and are the basis for calculating time-based metrics (MTTD/MTTR).
- Question 10Intermediate
Data Engineering · Understand and apply Splunk methods of data normalization
An engineer needs to extract a custom field
transaction_idfrom a proprietary application log for use in a Splunk Data Model. The logs are unstructured text.Which method ensures this field is available for Data Model acceleration?
Show answer & explanation
Correct answer: B
Data Models can use search-time extractions (IFX/Regex). While index-time extractions are possible, they are generally discouraged unless necessary for routing. Search-time extractions defined in props.conf are fully compatible with Data Model acceleration.
Ready for the real thing?
The full SPLK-5002 simulator has every exam-style question, timed mode, and instant scoring.