
SplunkCertified Cybersecurity Defense Engineer
Domain 4Objective 5
Compare and Validate Integrations and Automation Capabilities of Enterprise Security and SOAR. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 5)
Part of the Automation and Efficiency domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
7concepts
20%of the exam
Questions 21–23
- 21
What type of automation is primarily used by Enterprise Security to generate alerts?
Select an answer first - 22
A security team uses Splunk SOAR to automate incident response. They have a playbook that, on a new phishing incident, enriches the incident with threat intelligence and then creates a ticket in ServiceNow. The team wants to verify that the playbook is working correctly in production without affecting real incidents. What should they do?
Select an answer first - 23
A Splunk Enterprise Security administrator wants to automatically generate a notable event when a user fails authentication more than five times in ten minutes. They also want to run a script to disable the user's account when this occurs. What should they configure in ES?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSECURITY-DEFENSE-ENGINEER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.