Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps.


Question 381. What is the first phase of generic incident response?

  1. Recover
  2. Detect
  3. Eradicate
  4. Review

Correct Answer: 2. Detect

Explanation:

Detection is the first phase in Splunk Enterprise Security’s built-in Generic Incident Response plan. During this phase, analysts identify indications that a security event or incident may have occurred. Detection can originate from Splunk findings, third-party alerts, threat-intelligence matches, user reports, or other monitoring sources. The objective is to recognize potentially harmful activity early enough for analysts to begin analysis. Splunk’s current Generic Incident Response workflow progresses through detect, analyze, contain, eradicate, recover, and review phases, giving analysts a standardized structure for handling security incidents.

Question 382. What follows detection in generic incident response?

  1. Recovery
  2. Review
  3. Eradication
  4. Analysis

Correct Answer: 4. Analysis

Explanation:

Analysis follows detection in the Generic Incident Response workflow. During analysis, the security team examines available evidence to determine what happened, which entities are involved, the potential scope of compromise, and how serious the situation may be. In Splunk Enterprise Security, analysts can review findings, events, fields, notes, files, timelines, risk context, and threat intelligence within an investigation. Good analysis helps distinguish legitimate security incidents from benign or false-positive activity before disruptive response actions are taken.

Question 383. What is the goal of containment?

  1. Limit incident spread
  2. Rebuild dashboards
  3. Add threat feeds
  4. Increase logging volume

Correct Answer: 1. Limit incident spread

Explanation:

Containment aims to restrict the spread and impact of a confirmed or strongly suspected incident. Depending on the situation, containment can include isolating an endpoint, disabling an account, blocking malicious infrastructure, restricting network access, or stopping data exfiltration. The goal is to prevent additional harm while preserving enough evidence for continued investigation. Splunk’s Generic Incident Response plan includes containment before eradication and recovery, and specialized response plans such as Data Breach also include tasks related to containing exfiltration.

Question 384. What is eradication focused on?

  1. Initial detection
  2. Executive reporting
  3. Removing the incident cause
  4. Restoring dashboards

Correct Answer: 3. Removing the incident cause

Explanation:

Eradication focuses on removing the malicious presence or underlying cause of an incident after containment has limited further damage. Examples can include deleting malware, removing unauthorized accounts, closing persistence mechanisms, patching exploited vulnerabilities, or correcting malicious configuration changes. Containment and eradication are different: containment limits ongoing impact, while eradication removes the threat from the environment. Splunk’s built-in Generic Incident Response plan places eradication after containment and before recovery, reflecting this logical progression.

Question 385. What is recovery intended to do?

  1. Restore normal operations
  2. Find the initial alert
  3. Create new risk objects
  4. Suppress all detections

Correct Answer: 1. Restore normal operations

Explanation:

Recovery restores affected systems and services to normal or acceptable operation after the immediate threat has been contained and eradicated. Recovery may involve rebuilding systems, restoring data from trusted backups, re-enabling accounts, validating security controls, and monitoring closely for signs of recurrence. Analysts should avoid returning a system to production before confirming that the malicious activity and persistence mechanisms have been removed. Splunk’s Generic Incident Response plan includes recovery as the phase immediately before final review.

Question 386. What is the final generic response phase?

  1. Analyze
  2. Contain
  3. Recover
  4. Review

Correct Answer: 4. Review

Explanation:

Review is the final phase of Splunk’s Generic Incident Response plan. After technical remediation and recovery are complete, the security team should examine what happened, what controls succeeded or failed, how efficiently the incident was handled, and what improvements are needed. Lessons from the incident can lead to better detections, response procedures, logging, automation, and defensive controls. This phase supports continuous improvement rather than treating incident response as complete immediately after systems return to service.

Question 387. What should an analyst do before starting an investigation?

  1. Delete the finding
  2. Triage the finding
  3. Disable detections
  4. Clear the risk score

Correct Answer: 2. Triage the finding

Explanation:

Splunk’s Mission Control workflow recommends triaging a finding before starting a formal investigation. The analyst reviews the finding, assigns it if appropriate, updates its status, and examines enough context to determine whether deeper investigation is warranted. Triage helps prevent unnecessary case creation for clearly benign activity while ensuring significant findings receive structured follow-up. After triage, the analyst can select Start investigation and review events, additional fields, notes, files, and other contextual information.

Question 388. What does assigning a finding improve?

  1. Index performance
  2. Threat-feed quality
  3. Analyst accountability
  4. Sourcetype parsing

Correct Answer: 3. Analyst accountability

Explanation:

Assigning a finding or investigation to an analyst establishes clear ownership of the work. This improves coordination in a SOC because team members can see who is responsible for reviewing, investigating, and updating the case. Without ownership, several analysts may duplicate work or assume someone else is handling the issue. Splunk Mission Control includes assignment as an early triage step and supports continuing updates throughout the investigation so the broader team can understand progress and responsibilities.

Question 389. What does a Pending status indicate?

  1. Investigation is closed
  2. Risk equals zero
  3. Evidence was deleted
  4. Work is waiting on information or action

Correct Answer: 4. Work is waiting on information or action

Explanation:

A Pending status can be used when an investigation cannot progress until additional information, approval, automation, or help from another team becomes available. Splunk’s Mission Control workflow gives examples such as waiting for a crucial playbook or action approval. Using Pending accurately communicates that the investigation is still active but temporarily blocked. This is different from closing an investigation, which indicates that appropriate actions have been taken and the security incident has been resolved.

Question 390. What does escalation mean in a SOC?

  1. Passing a case to higher expertise or authority
  2. Deleting an alert
  3. Lowering risk
  4. Renaming a field

Correct Answer: 1. Passing a case to higher expertise or authority

Explanation:

Escalation occurs when an analyst transfers or raises a case to someone with greater authority, specialized expertise, or responsibility. A tier-one analyst might escalate suspected malware to an incident responder, threat hunter, or senior analyst, while a major business-impact event might require management or legal involvement. The SPLK-5001 blueprint expects candidates to understand the organization of a typical SOC and the responsibilities associated with analyst, engineer, and architect roles. Escalation helps ensure complex or high-impact incidents receive the appropriate expertise and decision-making authority.

Question 391. What should investigation notes document?

  1. Only usernames
  2. Only timestamps
  3. Evidence and analyst actions
  4. Only dashboard changes

Correct Answer: 3. Evidence and analyst actions

Explanation:

Investigation notes should document important evidence, reasoning, actions, observations, and context discovered during the case. Splunk Enterprise Security allows analysts to attach notes and supporting material to findings and investigations, helping other team members understand what has already been reviewed. Notes can include text, screenshots, log extracts, reference material, and other supporting evidence. Good documentation improves collaboration, supports later review, and reduces the chance that another analyst repeats work that has already been completed.

Question 392. Why attach files to investigation tasks?

  1. Increase index size
  2. Preserve supporting evidence
  3. Change the sourcetype
  4. Suppress findings

Correct Answer: 2. Preserve supporting evidence

Explanation:

Response-plan tasks can include files that support the investigation. These files may contain screenshots, reports, extracted evidence, external documentation, or other materials relevant to the analyst’s work. Keeping supporting material with the investigation makes the response process easier to review and allows other team members to see the same evidence. Splunk Enterprise Security response plans support files and notes at the task level, helping analysts document their progress while following standardized response procedures.

Question 393. What is an investigation type?

  1. A category of similar investigations
  2. A raw event format
  3. A CIM field
  4. A threat indicator

Correct Answer: 1. A category of similar investigations

Explanation:

An investigation type categorizes investigations that share characteristics such as source, severity, or another meaningful attribute. Splunk Enterprise Security allows organizations to associate an investigation type with a response plan. Once configured, new investigations of that type can automatically receive the appropriate standardized response workflow. This helps personalize response procedures while maintaining consistency. For example, account compromise investigations can follow one response plan while vulnerability-disclosure investigations follow another.

Question 394. What does a response-plan phase contain?

  1. Index buckets
  2. Tasks
  3. Sourcetypes
  4. Field aliases

Correct Answer: 4. Tasks

Explanation:

A response plan is organized into phases, and each phase contains tasks that analysts perform during investigation and response. For example, a phase might focus on containment and include specific tasks for isolating affected systems, disabling accounts, or blocking malicious indicators. Analysts complete the tasks and then complete the phase before moving through the rest of the plan. This phased structure turns high-level incident-response procedures into clear, trackable operational steps.

Question 395. Why use a standardized response plan?

  1. Reduce investigation consistency
  2. Ensure repeatable response steps
  3. Remove analyst ownership
  4. Increase false positives

Correct Answer: 2. Ensure repeatable response steps

Explanation:

Response plans standardize the phases and tasks analysts follow during security investigations. This helps different analysts respond consistently to similar incident types and reduces the chance that an important response step is forgotten. Splunk Enterprise Security includes built-in plans such as Generic Incident Response, Account Compromise, Data Breach, Suspicious Email, and Vulnerability Disclosure, while organizations can also create custom plans based on their own standard operating procedures. Standardization supports repeatability without preventing analysts from adapting to case-specific evidence.

Question 396. Which response plan fits suspected account theft?

  1. Vulnerability Disclosure
  2. Network Indicator Enrichment
  3. Account Compromise
  4. Generic Search Optimization

Correct Answer: 3. Account Compromise

Explanation:

Splunk Enterprise Security includes an Account Compromise response plan designed for potential compromise of system or application accounts. It provides phases and tasks relevant to investigating suspicious account activity and responding to the possible compromise. Choosing a response plan aligned to the incident type gives analysts a more relevant checklist than using unrelated procedures. Investigation types can also be linked with response plans so matching investigations automatically receive the appropriate workflow.

Question 397. What should happen before closing an investigation?

  1. Verify appropriate response actions are complete
  2. Delete all notes
  3. Remove the findings
  4. Disable the detection

Correct Answer: 2. Verify appropriate response actions are complete

Explanation:

An investigation should be closed only after the analyst has reached a conclusion and the appropriate response actions have been completed. Splunk’s Mission Control workflow places closure after triage, investigation, response, threat-intelligence review, status updates, and disposition selection. Closing too early can hide unfinished remediation or leave important follow-up work incomplete. The analyst should ensure the incident has been handled according to the response plan and that the investigation record accurately reflects the outcome and actions taken.

Question 398. What does disposition record?

  1. Search runtime
  2. Index location
  3. Event count
  4. Final analyst conclusion

Correct Answer: 4. Final analyst conclusion

Explanation:

Disposition records the analyst’s conclusion about the security activity after investigation. Splunk Enterprise Security provides outcomes such as true positive, benign positive, false positive, and undetermined. Disposition differs from workflow status: status describes where the investigation is in the process, while disposition describes what the analyst ultimately concluded about the event. Updating disposition before closure helps create useful feedback for detection tuning, reporting, and review of SOC performance.

Question 399. What is a true positive disposition?

  1. Legitimate activity correctly ignored
  2. Detection failed completely
  3. Confirmed malicious or policy-violating activity
  4. Investigation has not started

Correct Answer: 1. Confirmed malicious or policy-violating activity

Explanation:

A true positive disposition means the investigation determined that the security finding represented genuine unwanted or malicious activity rather than a false alarm. This conclusion should be based on evidence collected during analysis rather than only on the original detection. Recording accurate dispositions helps SOC teams understand detection effectiveness and identify which security controls are producing meaningful findings. Splunk Mission Control supports true positive as one of the available investigation outcomes alongside benign positive, false positive, and undetermined.

Question 400. What BEST completes incident response?

  1. Stop after containment
  2. Delete the investigation
  3. Restore service and review lessons learned
  4. Ignore detection improvements

Correct Answer: 3. Restore service and review lessons learned

Explanation:

Incident response is not complete immediately after the threat is contained. The organization should eradicate the threat, recover affected services, verify that normal operations can safely resume, and review the incident for lessons learned. Splunk’s Generic Incident Response plan explicitly progresses through detect, analyze, contain, eradicate, recover, and review. The review phase can identify opportunities to improve detections, automation, logging, controls, and operating procedures so the organization is better prepared for similar incidents in the future.