
SplunkCertified Cybersecurity Defense Engineer
Domain 4Objective 4
Automate Responses Using SOAR Playbooks. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 6)
Part of the Automation and Efficiency domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
20%of the exam
Questions 26–29
- 26
An organization uses a SOAR platform and wants to automatically block malicious IPs on their firewall. The firewall vendor provides an API. What is the recommended way to integrate this into a playbook?
Select an answer first - 27
A playbook is triggered by a new case in the ticketing system. The playbook needs to know the case ID and the reporter's email to send a notification. How should these values be provided to the playbook?
Select an answer first - 28
A playbook is designed to handle account lockout alerts. It should only disable the account if the alert severity is high and the account has not been disabled in the last 24 hours. The playbook is not behaving as expected; it disables accounts even for low-severity alerts. What is the most likely cause?
Select an answer first - 29
Which playbook element is used to repeat an action for each item in a list, such as a list of affected hosts?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSECURITY-DEFENSE-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.