
SplunkCertified Cybersecurity Defense Engineer
Domain 5Objective 1
Develop and Optimize Security Metrics. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 6)
Part of the Auditing and Reporting on Security Programs domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
7concepts
10%of the exam
Questions 26–30
- 26
A security analyst needs to present a monthly report to non-technical executives. The report should show whether the security program is improving. Which visualization approach is most effective?
Select an answer first - 27
To develop a metric on the number of malware infections blocked per month, which data source would you use?
Select an answer first - 28
A security team sets a target that 95% of critical alerts must be triaged within 15 minutes. What is this an example of?
Select an answer first - 29
During a quarterly review, a security team finds that a metric is no longer used by any stakeholder. What should they do?
Select an answer first - 30
A Splunk analyst is asked to develop a metric for 'time to patch' critical vulnerabilities. The available data sources are vulnerability scanner results and configuration management database (CMDB) records. Which approach would provide the most accurate metric?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.