
SplunkCertified Cybersecurity Defense Engineer
Domain 5Objective 1
Develop and Optimize Security Metrics. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 3)
Part of the Auditing and Reporting on Security Programs domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
10%of the exam
Questions 11–15
- 11
A security team wants to set a target for the metric 'percentage of endpoints with the latest antivirus signatures'. The current baseline is 95%. The team wants to improve but also wants a realistic target. What is the most appropriate target?
Select an answer first - 12
When selecting security metrics, what should be the primary consideration?
Select an answer first - 13
A Splunk engineer is asked to create a metric for 'dwell time' (time from compromise to detection). The available data sources are authentication logs, endpoint detection and response (EDR) alerts, and incident tickets. Which data source combination would provide the most accurate dwell time metric?
Select an answer first - 14
A Splunk analyst is asked to create a metric for 'time to detect' security incidents. The available data sources are firewall logs, endpoint detection and response (EDR) alerts, and ticketing system records. Which approach best derives this metric from the available data?
Select an answer first - 15
A Splunk analyst is asked to develop a metric for 'time to contain' a security incident. The available data sources are EDR alerts, firewall logs, and incident tickets. The analyst notices that the EDR alert timestamps are often delayed by several minutes due to data ingestion. How should the analyst handle this to ensure the metric is accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.