
SplunkCertified Cybersecurity Defense Engineer
Domain 5Objective 2
Build and Populate Effective Security Reports. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 3)
Part of the Auditing and Reporting on Security Programs domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
5concepts
10%of the exam
Questions 11–15
- 11
To populate a security report on malware detections, which field is essential to extract from the relevant data source?
Select an answer first - 12
A report on phishing emails shows a high number of detections from a specific email gateway. You notice that the counts are significantly higher than expected. What is the most likely cause of this discrepancy?
Select an answer first - 13
You are building a report on data exfiltration attempts. The report should include the source IP, destination IP, and the amount of data transferred. Which data source is most appropriate?
Select an answer first - 14
You are designing a security report for the IT operations team that will be used to identify systems with outdated antivirus definitions. Which report layout is most effective?
Select an answer first - 15
You need to populate a report on failed authentication attempts across the organization. The report should include the source IP, username, and destination host for each failure. Which data source and fields are most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.