Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part2 Q21-40

View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps.


Question 21. Which source best shows login activity?

  1. DNS logs
  2. Authentication logs
  3. Proxy logs
  4. Firewall logs

Correct Answer: 2. Authentication logs

Explanation:

Authentication logs record login attempts, successful and failed authentication, account usage, and related identity activity. They are especially useful when investigating account takeover, brute-force attempts, unusual login times, or access from unexpected locations. Splunk security products commonly use authentication data from sources such as Active Directory, VPN systems, cloud identity providers, and operating-system logs. Analysts can correlate authentication events with endpoint and network activity to determine whether a user account was used legitimately or maliciously. Splunk identifies authentication data as a core security data source for investigations and behavioral analytics.

Question 22. Which source best shows domain lookups?

  1. Endpoint logs
  2. Email logs
  3. IDS alerts
  4. DNS logs

Correct Answer: 4. DNS logs

Explanation:

DNS logs record queries and responses involving domain names and IP addresses. Analysts use them to identify communication with suspicious domains, newly registered domains, command-and-control infrastructure, malware download sites, or unusual lookup patterns. DNS telemetry is especially valuable because many attacks depend on domain resolution before making outbound connections. Splunk security analytics can combine DNS data with threat intelligence and endpoint activity to determine whether a host contacted a malicious or rare domain. Splunk-supported Windows data collection can also include DNS server debug logs where enabled.

Question 23. Which source best shows blocked network traffic?

  1. Firewall logs
  2. Registry logs
  3. Email logs
  4. DHCP logs

Correct Answer: 1. Firewall logs

Explanation:

Firewall logs commonly record permitted and denied network connections, including source and destination IP addresses, ports, protocols, and action results. These events are useful when investigating scanning, blocked command-and-control traffic, unauthorized access attempts, or suspicious outbound communication. Analysts can also use firewall telemetry to determine whether a system successfully communicated with an external host after an alert. Splunk identifies firewall data as an important security source for detecting compromised hosts, lateral movement, and other suspicious network behavior.

Question 24. Which source best shows executed processes?

  1. DNS logs
  2. Firewall logs
  3. Endpoint telemetry
  4. DHCP logs

Correct Answer: 3. Endpoint telemetry

Explanation:

Endpoint telemetry can provide visibility into processes, command lines, file changes, parent-child process relationships, registry modifications, and other host-level behavior. This makes endpoint data especially important when investigating malware execution, suspicious PowerShell use, credential dumping, persistence, or unusual administrative tools. Network logs may show that a system communicated with a suspicious destination, but endpoint data can reveal which process initiated that activity. Splunk Security Content includes Windows and other endpoint data sources that support behavior-based detections and investigations.

Question 25. Which source best shows visited URLs?

  1. Authentication logs
  2. Registry logs
  3. DHCP logs
  4. Proxy logs

Correct Answer: 4. Proxy logs

Explanation:

Web proxy logs commonly record requested URLs, destination domains, client IP addresses, user identities, HTTP methods, response codes, and sometimes transferred bytes. These fields make proxy data valuable for investigating phishing, malware downloads, suspicious web browsing, data exfiltration, or access to known malicious infrastructure. Splunk security analytics can use HTTP and proxy data to detect suspicious domains, anonymizers, storage sites, and unusual web transfers. Proxy logs are therefore an important source when the analyst needs to understand a user’s web activity.

Question 26. Which source best shows intrusion alerts?

  1. DHCP logs
  2. IDS/IPS logs
  3. DNS logs
  4. Badge logs

Correct Answer: 2. IDS/IPS logs

Explanation:

Intrusion Detection and Prevention System logs contain alerts generated when network traffic matches signatures, protocol anomalies, or other suspicious conditions. They may identify exploit attempts, reconnaissance, malware traffic, or policy violations. An analyst should not assume every IDS alert represents a confirmed compromise because false positives are possible. Instead, the alert should be correlated with endpoint, firewall, authentication, and other relevant evidence. Splunk recommends firewall and IDS/IPS data as important sources for security monitoring and investigation workflows.

Question 27. Which source can show registry changes?

  1. Windows endpoint data
  2. DNS data
  3. Firewall data
  4. NetFlow only

Correct Answer: 1. Windows endpoint data

Explanation:

Windows telemetry can include registry activity, allowing analysts to identify modifications associated with persistence, security-control changes, malware configuration, or system tampering. Splunk can collect Windows Registry data and file-system changes in addition to event logs, performance metrics, Active Directory data, and host information. Registry monitoring is particularly useful because attackers frequently modify registry keys to establish startup persistence or alter system behavior. Analysts should correlate suspicious registry changes with process creation and authentication data for stronger evidence.

Question 28. Which source best shows cloud API actions?

  1. Syslog only
  2. DNS only
  3. Cloud audit logs
  4. Badge logs

Correct Answer: 3. Cloud audit logs

Explanation:

Cloud audit logs record actions performed through cloud consoles, APIs, identities, and services. Examples include resource creation, privilege changes, policy updates, object access, or administrative API calls. These logs are essential when investigating suspicious cloud activity because many attacks occur through legitimate cloud APIs rather than traditional network exploits. Splunk Security Content includes data sources such as AWS CloudTrail and Azure identity or monitoring data. Analysts can correlate cloud audit events with identity, endpoint, and network evidence to understand the full sequence of activity.

Question 29. Which source best maps IP leases to hosts?

  1. DHCP logs
  2. Proxy logs
  3. IDS alerts
  4. Email logs

Correct Answer: 1. DHCP logs

Explanation:

DHCP logs help analysts determine which device was assigned a particular IP address at a specific time. This is important because endpoint IP addresses can change frequently. During an investigation, a firewall or proxy log may identify suspicious activity from an IP address, but DHCP data can help associate that address with the correct endpoint. Splunk identifies DHCP information as useful contextual data for entity resolution and understanding network behavior. Accurate time correlation is important because the same IP address may belong to different devices at different times.

Question 30. Which source best shows email delivery details?

  1. NetFlow
  2. Registry logs
  3. NTP logs
  4. Email logs

Correct Answer: 4. Email logs

Explanation:

Email logs can contain sender, recipient, subject, message identifier, delivery status, attachment information, and mail-server routing details. These fields are useful when investigating phishing, business email compromise, malicious attachments, or suspicious forwarding behavior. Analysts can correlate email events with authentication logs to identify compromised mail accounts and with endpoint telemetry to determine whether a user opened or executed a malicious attachment. Splunk identifies email data as an important security source for behavioral and account-focused investigations.

Question 31. Which source best shows network flow metadata?

  1. Registry logs
  2. Email logs
  3. Flow data
  4. Badge data

Correct Answer: 3. Flow data

Explanation:

Network flow data summarizes communications between systems without necessarily storing complete packet contents. Typical fields include source and destination IP addresses, source and destination ports, protocol, byte counts, packet counts, and timing information. Analysts can use flow data to identify unusual outbound connections, lateral movement, scanning, large transfers, or communications with rare destinations. Flow telemetry is especially useful when full packet capture is unavailable because it provides broad network visibility with lower storage requirements than retaining every packet.

Question 32. Which source best confirms malware detection?

  1. DNS logs
  2. Antivirus or EDR logs
  3. DHCP logs
  4. NTP logs

Correct Answer: 2. Antivirus or EDR logs

Explanation:

Antivirus and endpoint detection and response products generate alerts about malware, suspicious processes, quarantined files, exploit behavior, and other endpoint threats. These logs often contain host names, usernames, file paths, hashes, process information, and detection names. They can provide strong evidence that malicious activity occurred on an endpoint, although analysts should still correlate the alert with additional data. Splunk identifies malware or antivirus data as an important source for security monitoring alongside authentication and firewall information.

Question 33. Which source best shows VPN connections?

  1. Proxy logs
  2. DNS logs
  3. Registry logs
  4. VPN logs

Correct Answer: 4. VPN logs

Explanation:

VPN logs record remote-access sessions, including usernames, source IP addresses, assigned internal addresses, connection times, authentication outcomes, and session durations. These events are valuable when investigating account compromise or remote access from unusual geographic locations. VPN data can also help analysts understand which remote user had a particular internal address during an incident. Splunk identifies VPN telemetry as an important data source for compromised-user analysis, contextual intelligence, and identity-related investigations.

Question 34. Which model normalizes security fields?

  1. Common Information Model
  2. OSI model
  3. TCP model
  4. DNS model

Correct Answer: 1. Common Information Model

Explanation:

Splunk’s Common Information Model, or CIM, provides standardized field names and data models across different vendors and technologies. For example, authentication products from different vendors can map their data into a consistent Authentication data model. This allows searches, correlation rules, and dashboards to work across normalized data rather than being rewritten for every product. Splunk Enterprise Security relies heavily on CIM-compliant data models, and Splunk recommends using CIM-compatible technology add-ons when onboarding security data sources.

Question 35. What commonly maps vendor data to CIM?

  1. Dashboards only
  2. Splunk add-ons
  3. Lookup files only
  4. Alert actions only

Correct Answer: 2. Splunk add-ons

Explanation:

Splunk technology add-ons commonly parse vendor-specific events, extract fields, assign event types or tags, and map data to the Common Information Model. This normalization lets Splunk Enterprise Security use standardized data models across different vendors. Splunk’s data-source planning guidance recommends identifying an appropriate add-on for each security technology and using CIM-compatible content where possible. Without correct normalization, security dashboards and correlation searches may miss data or require vendor-specific searches.

Question 36. Why is CIM normalization useful?

  1. It deletes raw data
  2. It disables indexes
  3. It standardizes fields across products
  4. It removes timestamps

Correct Answer: 3. It standardizes fields across products

Explanation:

CIM normalization makes data from different products easier to search together by mapping equivalent concepts to common field names. For example, several authentication systems may use different vendor-specific fields for usernames, but CIM can map them to a standard field. This allows one detection or dashboard to work across multiple data sources. Splunk Enterprise Security uses CIM-standardized data models for dashboards, views, and correlation searches. Normalization does not remove the original raw events; it adds consistent knowledge and structure for analysis.

Question 37. Which source helps investigate physical access?

  1. Badge access logs
  2. DNS logs
  3. Proxy logs
  4. NetFlow

Correct Answer: 2. Badge access logs

Explanation:

Badge access logs can show when an employee entered or attempted to enter a physical location. This information can add valuable context to a cybersecurity investigation. For example, if a user account logs in from an office system while badge records show the user never entered the building, the discrepancy may increase suspicion of account compromise. Splunk identifies badge access as one of the contextual data sources that can support compromised-account and behavioral investigations. Physical and digital evidence become more useful when correlated by user and time.

Question 38. Which source best shows HTTP activity?

  1. Registry data
  2. Badge logs
  3. DHCP data
  4. Web or proxy logs

Correct Answer: 4. Web or proxy logs

Explanation:

Web and proxy logs provide visibility into HTTP or HTTPS-related activity, including domains, URLs, clients, servers, response codes, transferred bytes, and sometimes user identities. Analysts can use this telemetry to investigate malware downloads, phishing links, suspicious storage services, anonymizers, or possible data exfiltration. Splunk’s security analytics documentation identifies HTTP data as valuable for detecting suspicious domains, malicious downloads, and large transfers to storage services. These logs are therefore central to many web-based investigations.

Question 39. Which source best shows Windows logons?

  1. Windows Security Event logs
  2. LLDP data
  3. SNMP only
  4. DHCP only

Correct Answer: 3. Windows Security Event logs

Explanation:

Windows Security Event logs contain important authentication, account-management, and security events generated by Windows systems and Active Directory. Analysts can use them to investigate successful or failed logons, account changes, privilege activity, and other identity-related events. Splunk’s Windows Add-on provides supported inputs and CIM-compatible knowledge for collecting Windows Security data. Accurate Windows auditing must be configured because some events are not logged unless appropriate audit policies are enabled.

Question 40. Which data strategy BEST supports investigations?

  1. Use multiple relevant data sources
  2. Use only firewall logs
  3. Use only endpoint alerts
  4. Use only authentication logs

Correct Answer: 1. Use multiple relevant data sources

Explanation:

Strong investigations rarely depend on a single log source. Authentication data may show who logged in, endpoint telemetry may show what process executed, DNS and proxy logs may show external communication, and firewall or flow data may confirm whether connections succeeded. Combining multiple sources provides stronger context and reduces the risk of drawing conclusions from incomplete evidence. Splunk’s security guidance emphasizes onboarding different security data sources and normalizing them through CIM so analysts can correlate activity across technologies.