Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 2Objective 1

Create and Tune Detections (i.e. Correlation Search). CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 4)

Part of the Detection Engineering domain, which accounts for 40% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~12–20 in this domain), expect 2–4 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
40%of the exam

Questions 16–20

  1. 16foundation · easy

    Which indexing consideration can improve the performance of a correlation search?

    Select an answer first
  2. 17expert · hard

    A correlation search for 'possible brute force' uses a static threshold of 20 failed logins per hour. The environment has a mix of systems: some are internet-facing with high login traffic, others are internal with low traffic. The search generates many false positives on internet-facing systems and misses attacks on internal systems. The engineer wants to improve accuracy without increasing operational overhead significantly. Which approach is most effective?

    Select an answer first
  3. 18expert · hard

    A detection engineer is tuning a correlation search for 'possible data exfiltration' that alerts on large outbound transfers. The search currently uses a static threshold of 1 GB per hour, but it generates many false positives from a backup server that routinely transfers 5 GB hourly. The engineer wants to reduce false positives without missing real exfiltration from other hosts. Which tuning action is most effective?

    Select an answer first
  4. 19application · medium

    A correlation search for 'multiple failed logins' is generating too many alerts from a specific application that uses service accounts with predictable retry patterns. The engineer wants to reduce these false positives without affecting detection for real user accounts. Which tuning action is most appropriate?

    Select an answer first
  5. 20expert · hard

    A detection engineer has developed a correlation search to detect 'pass-the-hash' attacks. The engineer wants to validate the detection before deployment. The team has a dataset of known-good authentication events and a dataset of known-bad pass-the-hash events. The engineer runs the search on both datasets and observes that it alerts on all known-bad events but also alerts on 5% of known-good events. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.