Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
SPLUNK

Splunk Certified Cybersecurity Defense Engineer

CYBERSECURITY-DEFENSE-ENGINEERSplunk Cybersecurity Defense Engineer

The Splunk Certified Cybersecurity Defense Engineer certification validates your ability to optimize SOC workflows using Splunk Enterprise Security and Splunk SOAR. You'll learn to craft and tune effective detections, incorporate threat intelligence, and build automations that follow industry best practices. This credential is for security professionals ready to advance from analyst to defense engineering roles.

512 practice questions · Updated 2026-07-30

5Domains
19Objectives
140Concepts
512Questions

CYBERSECURITY-DEFENSE-ENGINEER Curriculum

Every domain, objective, and concept the CYBERSECURITY-DEFENSE-ENGINEER exam measures.

  1. Data Review Process
  2. Data Analysis Techniques
  3. Data Quality Assessment
  4. Data Correlation
  5. Data Visualization
  6. Data Enrichment
  7. Data Filtering and Reduction
  8. Data Validation
  9. Data Interpretation
  10. Data Documentation
  1. Indexing Performance Fundamentals
  2. Index Design and Configuration
  3. Data Input Management
  4. Indexer Clustering
  5. Monitoring and Troubleshooting Indexing
  6. Index Maintenance Tasks
  7. Performance Tuning Techniques
  1. Splunk Common Information Model (CIM)
  2. CIM Data Models
  3. Field Normalization Techniques
  4. Event Tagging for Normalization
  5. CIM Compliance Validation
  6. Custom Data Model Extensions

  1. Risk-based modifier fundamentals
  2. Risk score and risk object concepts
  3. Creating risk-based modifiers
  4. Applying risk-based modifiers to detections
  5. Risk-based detection tuning
  6. Testing and validating risk-based detections
  1. Notable Event Generation
  2. Correlation Searches
  3. Notable Event Attributes
  4. Notable Event Actions
  5. Notable Event Suppression
  6. Notable Event Throttling
  7. Notable Event Enrichment
  8. Notable Event Review Workflow
  9. Notable Event Tuning
  10. Notable Event Testing and Validation
  1. Detection lifecycle phases
  2. Detection requirements gathering
  3. Detection development process
  4. Detection deployment and integration
  5. Detection monitoring and tuning
  6. Detection retirement and review

  1. Threat Intelligence Sources
  2. Threat Intelligence Collection Methods
  3. Threat Intelligence Evaluation
  4. Threat Intelligence Integration
  5. Threat Intelligence Development
  6. Threat Intelligence Dissemination
  1. Risk Assessment Frameworks
  2. Threat Modeling
  3. Asset Classification and Valuation
  4. Vulnerability Assessment
  5. Risk Scoring and Prioritization
  6. Detection Engineering Prioritization
  7. MITRE ATT&CK Framework
  8. Risk Treatment and Mitigation
  9. Continuous Monitoring and Review
  1. Documentation Standards
  2. SOP Structure
  3. Process Documentation
  4. Procedure Writing
  5. Version Control
  6. Audience Consideration
  7. Review and Approval Workflow
  8. Maintenance and Updates

  1. SOP Automation Workflow Design
  2. Orchestration Tool Integration
  3. Playbook Development
  4. API and Webhook Utilization
  5. Conditional Logic and Decision Trees
  6. Error Handling and Retry Mechanisms
  7. Security and Access Control in Automation
  8. Testing and Validation of Automation
  9. Monitoring and Logging Automation
  10. Documentation and Maintenance of SOPs

Optimize Case Management.

9 concepts · 34 questions
  1. Case Lifecycle Management
  2. Case Assignment and Ownership
  3. Case Prioritization and Triage
  4. Case Collaboration and Communication
  5. Case Automation Workflows
  6. Case Metrics and Reporting
  7. Case Integration with SOAR
  8. Case Data Enrichment
  9. Case Audit and Compliance

Describe and utilize REST APIs.

6 concepts · 19 questions
  1. REST API Fundamentals
  2. Authentication for Splunk REST API
  3. Common Splunk REST API Endpoints
  4. Making REST API Calls
  5. Handling API Responses
  6. Automating Tasks with REST API
  1. SOAR playbook fundamentals
  2. Playbook triggers and inputs
  3. Playbook actions and logic
  4. Integration with security tools
  5. Playbook testing and debugging
  6. Playbook versioning and management
  7. Playbook performance and optimization
  1. Integration capabilities of Enterprise Security
  2. Integration capabilities of SOAR
  3. Automation capabilities of Enterprise Security
  4. Automation capabilities of SOAR
  5. Comparison of integration approaches
  6. Comparison of automation approaches
  7. Validation of integration and automation capabilities

Develop and optimize security metrics.

7 concepts · 31 questions
  1. Define security metrics
  2. Select relevant metrics
  3. Develop metrics from data sources
  4. Establish baselines and targets
  5. Optimize metrics for actionability
  6. Visualize and report metrics
  7. Review and improve metrics
  1. Security report structure
  2. Data sources for reports
  3. Report generation techniques
  4. Report scheduling and distribution
  5. Report validation and accuracy
  1. Dashboard design principles
  2. Dashboard creation in Splunk
  3. Dashboard population with search results
  4. Dashboard data sources and indexes
  5. Dashboard visualization types
  6. Dashboard interactivity and drilldowns
  7. Dashboard sharing and permissions
  8. Dashboard performance optimization
  9. Dashboard maintenance and lifecycle
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CYBERSECURITY-DEFENSE-ENGINEER, so none is invented.