SPLK-5002 Sample Questions

SPLK-5002 Sample Questions & Answers

Creating and refining correlation searches as detections, with risk-based modifiers, carries by far the most weight, next to data normalization, developing threat intelligence, automating response through REST APIs, and reporting on security metrics.

Launch the full SPLK-5002 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Automation and Efficiency · Compare ES and SOAR automation capabilities

    When integrating Splunk Enterprise Security (ES) with Splunk SOAR, an administrator wants to ensure that when a Notable Event's status is changed to 'Closed' in ES, the corresponding container in SOAR is also closed automatically.

    Which feature must be configured to enable this synchronization?

    Show answer & explanation

    Correct answer: B

    The Splunk App for SOAR Export (or Phantom App) configured on the search head allows for bidirectional synchronization. This ensures that status changes in ES notables are reflected in SOAR containers, and vice versa.

  2. Question 2Intermediate

    Detection Engineering · Create and tune detections

    A detection engineer is reviewing the efficacy of a specific correlation search. They notice that the search generates a high volume of alerts for a specific administrative subnet (10.10.5.0/24) performing legitimate scanning activities.

    What is the most effective way to suppress these specific alerts without disabling the detection for the rest of the network?

    Show answer & explanation

    Correct answer: B

    Using a managed lookup for whitelisting is the best practice. It separates the detection logic from the exclusion data, making it easier to maintain and audit changes to the whitelist without editing the core SPL of the correlation search.

  3. Question 3Beginner

    Detection Engineering · Incorporate context into detections

    True or False: In Splunk Enterprise Security, the Asset and Identity frameworks can automatically enrich notable events with departmental information, but they cannot effectively prioritize alerts based on the 'criticality' field of an asset.

    Show answer & explanation

    Correct answer: B

    This is False. The Asset and Identity frameworks are explicitly designed to prioritize alerts. By defining the 'priority' or 'criticality' category for assets (e.g., PCI servers, C-level laptops), ES can calculate a higher urgency for Notable Events involving those assets.

  4. Question 4Beginner

    Auditing and Reporting on Security Programs · Develop and optimize security metrics

    A security manager requires a monthly report detailing the 'Mean Time to Detect' (MTTD) and 'Mean Time to Respond' (MTTR) for the SOC.

    Which Splunk Enterprise Security dashboard provides these metrics out-of-the-box?

    Show answer & explanation

    Correct answer: A

    The SOC Operations dashboard (sometimes labeled Incident Review Operations in newer versions) specifically tracks the efficiency of the SOC, including key performance indicators like MTTD, MTTR, and investigations per analyst.

  5. Question 5Intermediate

    Detection Engineering · Create and tune detections

    You are creating a new correlation search to detect 'Brute Force Access' attempts. You want to ensure that if the search runs every 5 minutes and detects an attack, it creates a Notable Event, but does NOT create another duplicate event for the same user and destination for at least 1 hour.

    Which configuration setting handles this requirement?

    Show answer & explanation

    Correct answer: A

    Window Throttling (configured in the correlation search editor) allows you to suppress subsequent alerts based on a set of fields (e.g., user, dest) for a specified duration (e.g., 1 hour), preventing alert fatigue.

  6. Question 6Advanced

    Building Effective Security Processes and Programs · Research, incorporate and develop threat intelligence

    Case Study: GlobalFinance Corp

    GlobalFinance Corp has a distributed Splunk environment. They are implementing a Threat Intelligence program. They have three requirements:

    1. Ingest a paid STIX/TAXII feed from 'VendorX'.
    2. Automatically verify if any internal IP addresses have communicated with malicious IPs from this feed in the last 24 hours.
    3. If a match is found, raise a 'Critical' Notable Event.

    The engineer has configured the Threat Intelligence Download in Enterprise Security to fetch the feed.

    What is the next logical step to automate the detection of historical matches (Requirement 2)?

    Show answer & explanation

    Correct answer: C

    Splunk Enterprise Security includes default correlation searches like 'Threat - Threat List Activity - Rule' that automatically compare incoming events (or data model summaries) against the threat intelligence collections. Enabling and tuning this rule satisfies the requirement to detect matches.

  7. Question 7Intermediate

    Detection Engineering · Create and tune detections

    When mapping a detection to the MITRE ATT&CK framework within Splunk Enterprise Security, which field is primarily used to link the correlation search to a specific Technique ID (e.g., T1059)?

    Show answer & explanation

    Correct answer: A

    In modern Splunk ES versions, the 'Annotations' framework is used. You add an annotation with the name 'mitre_attack' and the value as the Technique ID (e.g., T1059).

  8. Question 8Intermediate

    Automation and Efficiency · Automate responses using SOAR playbooks

    A SOC team wants to automate the 'Containment' phase of their Incident Response SOP. They decide to use a Splunk SOAR playbook.

    Which of the following describes the correct order of operations for a robust containment playbook?

    Show answer & explanation

    Correct answer: B

    A robust containment workflow should always include a human-in-the-loop (Prompt) to avoid accidental outages, followed by the action execution, and crucially, a verification step to ensure the action worked before updating the ticket.

  9. Question 9Beginner

    Building Effective Security Processes and Programs · Optimize Case Management

    What is the primary function of the 'Notable Event Status' transition in the Incident Review dashboard?

    Show answer & explanation

    Correct answer: D

    Status transitions are the core mechanism for tracking investigation progress. They allow the SOC to understand workload and are the basis for calculating time-based metrics (MTTD/MTTR).

  10. Question 10Intermediate

    Data Engineering · Understand and apply Splunk methods of data normalization

    An engineer needs to extract a custom field transaction_id from a proprietary application log for use in a Splunk Data Model. The logs are unstructured text.

    Which method ensures this field is available for Data Model acceleration?

    Show answer & explanation

    Correct answer: B

    Data Models can use search-time extractions (IFX/Regex). While index-time extractions are possible, they are generally discouraged unless necessary for routing. Search-time extractions defined in props.conf are fully compatible with Data Model acceleration.

Ready for the real thing?

The full SPLK-5002 simulator has every exam-style question, timed mode, and instant scoring.