Exam SPLK-5002 Topic 1 Question 48 Discussion

Actual exam question for Splunk's SPLK-5002 exam
Question #: 48
Topic #: 1
In which threat intelligence KV store would a list of malicious domains (FQDNs) be stored?

Suggested Answer: A Vote an answer

The correct collection is service_intel . Splunk Enterprise Security ' s Threat Intelligence Framework separates indicators into intelligence collections according to the type of observable being represented. Fully Qualified Domain Names are service-oriented network identifiers and are handled through the service intelligence collection in the context tested by this question.
This classification matters because the Threat Intelligence Framework must know which event fields and indicator types can be meaningfully compared. A domain such as malicious.example.com is semantically different from a raw IPv4/IPv6 address, a certificate fingerprint, or a complete HTTP URL. The ip_intel collection is intended for IP-oriented indicators, while certificate_intel deals with certificate-related intelligence. http_intel is associated with HTTP-oriented indicators such as URLs and related HTTP observables rather than the standalone FQDN type being asked about here.
Detection engineering depends on this normalization because matching searches must compare compatible indicator types. Correct placement also supports deduplication, expiration, weighting, threat matching, and downstream enrichment of security findings.
Study Guide topics: Threat Intelligence Framework, KV Store collections, indicator normalization, FQDN intelligence, threat matching, intelligence enrichment.

by kateryna.kutova at Sep 16, 2026, 03:11 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
kateryna.kutova
2026-09-16 03:11:00
Selected Answer: B
http_intel-Contains URL and HTTP-based indicators used for detecting malicious or suspicious web activity. from https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.7/threat-intelligence/threat-intelligence-kv-store-collections-in-splunk-enterprise-security
upvoted 1 times
...
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10