View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps.
Question 141. What is the first Cyber Kill Chain stage?
- Installation
- Reconnaissance
- Exploitation
- Command and control
Correct Answer: 2. Reconnaissance
Explanation:
Reconnaissance is the first stage of the traditional Cyber Kill Chain. During this phase, an attacker gathers information about the target, such as internet-facing systems, employees, technologies, vulnerabilities, or exposed services. The objective is to identify possible entry points before launching an attack. Security analysts can look for evidence such as scanning, enumeration, repeated requests, or suspicious open-source intelligence activity. Splunk describes the Cyber Kill Chain as a seven-stage model beginning with reconnaissance and progressing toward actions on objectives.
Question 142. What follows reconnaissance?
- Installation
- Exploitation
- Command and control
- Weaponization
Correct Answer: 4. Weaponization
Explanation:
Weaponization is the stage in which an attacker prepares the malicious capability that will be used against the target. This may involve combining an exploit with malware, creating a malicious document, or preparing another payload suitable for the planned delivery method. The attacker has already collected target information during reconnaissance and now prepares the attack package. Understanding this stage helps analysts distinguish preparatory attacker activity from later stages such as delivery, exploitation, or installation. Splunk’s Cyber Kill Chain description places weaponization directly after reconnaissance.
Question 143. What is the delivery stage?
- Sending the malicious payload
- Installing persistence
- Collecting data
- Destroying evidence
Correct Answer: 1. Sending the malicious payload
Explanation:
Delivery is the stage in which the attacker sends the prepared malicious content to the intended target. Common delivery methods include phishing email, malicious websites, infected downloads, removable media, or compromised software distribution. Delivery itself does not necessarily mean the exploit has succeeded. Analysts may investigate email logs, proxy data, endpoint telemetry, and web activity to determine how the payload reached the environment. In the Cyber Kill Chain, delivery follows weaponization and occurs before exploitation.
Question 144. What happens during exploitation?
- Data is archived
- C2 is established
- A vulnerability is triggered
- Persistence is removed
Correct Answer: 3. A vulnerability is triggered
Explanation:
Exploitation occurs when the attacker takes advantage of a vulnerability, weakness, or unsafe user action to execute malicious activity. Examples include exploiting a software flaw, convincing a user to enable a macro, or abusing an exposed application weakness. This phase moves the attack from delivered content toward actual compromise. Analysts may find evidence in endpoint process logs, application errors, exploit detections, IDS alerts, or unusual child processes. The Cyber Kill Chain places exploitation after delivery and before installation.
Question 145. What is the installation stage?
- Establishing malware or persistence
- Sending phishing mail
- Scanning the target
- Building a threat feed
Correct Answer: 1. Establishing malware or persistence
Explanation:
Installation is the stage where malicious code, persistence mechanisms, or attacker tooling becomes established on the compromised system. Examples include installing malware, creating startup persistence, modifying services, or placing tools that can be reused later. Analysts may investigate process creation, file writes, registry changes, scheduled tasks, services, and endpoint detections. Installation helps the attacker maintain access after the original exploit or user interaction has completed. It follows exploitation in the traditional Cyber Kill Chain.
Question 146. What is command and control?
- Data classification
- Risk scoring
- Asset inventory
- Remote attacker communication
Correct Answer: 4. Remote attacker communication
Explanation:
Command and control is the stage in which a compromised system communicates with infrastructure controlled by the attacker. Through this channel, the attacker may issue commands, download tools, maintain remote access, or prepare additional activity. Analysts can hunt for beaconing, suspicious domains, unusual outbound connections, or processes contacting rare destinations. The Cyber Kill Chain places command and control after installation and before the final actions-on-objectives stage. Detecting and blocking C2 can interrupt an intrusion even after initial compromise.
Question 147. What is the final Kill Chain stage?
- Weaponization
- Actions on objectives
- Reconnaissance
- Delivery
Correct Answer: 2. Actions on objectives
Explanation:
Actions on objectives is the final stage of the traditional Cyber Kill Chain. At this point, the attacker attempts to accomplish the purpose of the intrusion. Objectives may include stealing data, disrupting systems, conducting espionage, deploying ransomware, or modifying sensitive information. Analysts should correlate activity from earlier stages to understand how the attacker reached this point. Splunk’s description of the seven-stage Kill Chain lists actions on objectives after command and control.
Question 148. Why use the Cyber Kill Chain?
- Replace all detections
- Store threat intelligence
- Understand attack progression
- Normalize CIM fields
Correct Answer: 3. Understand attack progression
Explanation:
The Cyber Kill Chain helps analysts understand how an intrusion progresses through distinct attack stages. Mapping observed evidence to those stages can clarify what the attacker has already accomplished and what may happen next. It can also help defenders identify where controls detected or disrupted the attack. Splunk notes that threat hunters use frameworks such as Kill Chain and MITRE ATT&CK to understand adversary behavior and adapt hunting approaches to their environment.
Question 149. What does the Diamond Model connect?
- User, role, index, sourcetype
- Alert, lookup, macro, dashboard
- Risk, urgency, status, owner
- Adversary, capability, infrastructure, victim
Correct Answer: 4. Adversary, capability, infrastructure, victim
Explanation:
The Diamond Model of Intrusion Analysis describes an intrusion event using four core features: adversary, capability, infrastructure, and victim. The model helps analysts organize relationships between who is attacking, what tools or techniques they use, what infrastructure supports the activity, and which victim is targeted. This structured view can make pivoting easier during an investigation. Splunk’s Cybersecurity Defense Analyst learning material identifies the Diamond Model alongside MITRE ATT&CK and the Cyber Kill Chain as an analytic framework candidates should understand.
Question 150. What does the adversary vertex represent?
- Threat actor
- Malware hash
- Victim host
- Proxy server
Correct Answer: 1. Threat actor
Explanation:
In the Diamond Model, the adversary represents the person, group, or organization responsible for malicious activity. The analyst may not always know the true identity of the adversary, but available evidence can still describe behavior, objectives, or relationships with infrastructure and capabilities. The model encourages analysts to connect the adversary with the tools being used, the systems supporting the attack, and the victim. Splunk includes the Diamond Model in its Cybersecurity Defense Analyst learning content as one of the main analytic frameworks.
Question 151. What does capability represent?
- Victim business unit
- Attacker infrastructure
- Tools or techniques used
- Analyst owner
Correct Answer: 3. Tools or techniques used
Explanation:
The capability vertex in the Diamond Model represents the means the adversary uses to perform the intrusion. This can include malware, exploit techniques, scripts, phishing kits, credential theft methods, or other attack capabilities. Analysts can pivot from a known capability to infrastructure or victims that show related evidence. Separating capability from infrastructure is useful because the same tool may be used through several different servers or domains. Splunk identifies the Diamond Model as part of the analytical framework knowledge relevant to defense analysts.
Question 152. What does infrastructure represent?
- Analyst workstation
- Systems supporting the attack
- Victim identity
- SOC policy
Correct Answer: 2. Systems supporting the attack
Explanation:
Infrastructure in the Diamond Model includes resources used to support attacker operations, such as command-and-control servers, phishing domains, redirectors, malicious websites, or compromised hosts. Analysts can use infrastructure indicators to search historical security data and identify additional victims or related campaigns. Infrastructure can change frequently, which is why behavioral context and other model vertices remain important. The model gives analysts a structured way to connect infrastructure with adversaries, capabilities, and victims.
Question 153. What does the victim vertex represent?
- Targeted person or system
- Malware family
- Attacker domain
- Risk threshold
Correct Answer: 1. Targeted person or system
Explanation:
The victim vertex represents the person, organization, account, system, or other entity targeted by the adversary. Understanding the victim helps analysts evaluate attack scope, business impact, and likely attacker objectives. Victim characteristics may also reveal why a particular campaign chose certain targets. By linking victim data with attacker infrastructure and capabilities, analysts can identify additional related activity or uncover common targeting patterns. Splunk includes the Diamond Model in its defense analyst training path for structured intrusion analysis.
Question 154. What does triage prioritize?
- Index buckets
- Dashboard colors
- Data models
- Findings needing attention
Correct Answer: 4. Findings needing attention
Explanation:
Triage is the process of reviewing and prioritizing security findings so analysts focus first on the items that present the greatest potential threat. In Splunk Enterprise Security, Incident Review supports sorting, filtering, ownership, status updates, urgency, and risk analysis to make triage more efficient. Analysts should examine context rather than treating every notable identically. Effective triage improves response speed by directing attention toward higher-value security events.
Question 155. Which field helps prioritize notables?
- Source type
- Urgency
- SPL length
- Dashboard owner
Correct Answer: 2. Urgency
Explanation:
Urgency is one of the primary fields used to prioritize notables in Incident Review. Splunk Enterprise Security supports levels including informational, low, medium, high, critical, and unknown. Analysts can sort or filter by urgency so the most important findings receive attention first. Splunk calculates urgency using factors such as correlation-search severity and asset or identity priority. Urgency should still be evaluated with contextual evidence before final incident classification.
Question 156. What does status New mean?
- Case is closed
- Action is pending
- Event has not been reviewed
- Resolution verified
Correct Answer: 3. Event has not been reviewed
Explanation:
Splunk Enterprise Security uses New as the default status for a notable event that has not yet been reviewed. Once an analyst begins working the event, the status can be changed to In Progress. Other supported statuses include Pending, Resolved, and Closed. Maintaining accurate status values helps teams understand which findings are untouched, actively investigated, awaiting action, or completed. Splunk’s Incident Review documentation explicitly defines New as an event that has not yet been reviewed.
Question 157. What does status In Progress mean?
- Analyst is investigating
- Event is deleted
- Risk is zero
- Case is verified closed
Correct Answer: 2. Analyst is investigating
Explanation:
In Progress indicates that an owner is actively investigating the notable event. This status helps other SOC analysts avoid duplicating work and shows supervisors which findings are currently being handled. Splunk Incident Review allows analysts to update both status and ownership as part of normal triage and investigation. Maintaining the correct workflow state improves coordination, reporting, and accountability across the SOC.
Question 158. What does status Closed mean?
- Analyst started work
- Action is pending
- Cause is addressed only
- Resolution has been verified
Correct Answer: 4. Resolution has been verified
Explanation:
Splunk defines Closed as the workflow state in which resolution has been verified. This differs from Resolved, where the owner has addressed the cause but is still waiting for verification. Using both states allows the SOC to distinguish between remediation that has been performed and remediation that has been confirmed. Accurate closure status improves investigation tracking and helps ensure that findings are not considered complete before the resolution is validated.
Question 159. What are contributing events?
- Events that caused the notable
- Deleted indexes
- User role definitions
- Dashboard panels
Correct Answer: 3. Events that caused the notable
Explanation:
Contributing events are the underlying events associated with the creation of a notable. Analysts can review them to understand exactly what activity caused a correlation search or detection to trigger. Splunk’s Incident Review investigation workflow specifically recommends examining contributing events, correlation-search details, risk scores, and notable history. These events provide the evidence required to validate whether a notable represents benign activity, a false positive, or a genuine security incident.
Question 160. What BEST supports incident triage?
- Review urgency, evidence, risk, and context
- Close every alert
- Ignore ownership
- Use one field only
Correct Answer: 1. Review urgency, evidence, risk, and context
Explanation:
Effective triage requires more than reading an alert title. Analysts should consider urgency, contributing events, associated risk, affected assets or identities, investigation history, ownership, and relevant contextual evidence. Splunk Enterprise Security Incident Review provides these fields and allows sorting and filtering so analysts can focus on the highest-priority threats. Reviewing several sources of context reduces premature conclusions and supports faster, more accurate decisions about escalation, remediation, or closure.