
SplunkCertified Cybersecurity Defense Engineer
Domain 4Objective 1
Develop Automation and Orchestration for Standard Operating Procedures. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 1)
Part of the Automation and Efficiency domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
20%of the exam
Questions 1–5
- 1
A Splunk admin is integrating Splunk with a ticketing system via its REST API. The API has a rate limit of 10 requests per minute. The admin expects a burst of alerts that could exceed this limit. What should the admin do to ensure all alerts are processed without hitting the rate limit?
Select an answer first - 2
An automated workflow calls an external API to block an IP address. The API occasionally returns a 503 (service unavailable) error. The workflow should retry the call, but only a limited number of times, and then alert an analyst if it still fails. What is the best error-handling approach?
Select an answer first - 3
Which of the following is an example of a step that would be included in a playbook for a phishing email incident?
Select an answer first - 4
A Splunk admin is setting up an automation that uses a service account with elevated privileges to perform actions. The admin is concerned about the risk of credential misuse. What is the best practice to minimize this risk?
Select an answer first - 5
A Splunk environment must trigger a SOAR playbook when a specific alert fires. The SOAR API requires mutual TLS (mTLS) for authentication. The Splunk admin has the client certificate and key. Which configuration is correct?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.