Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 1Objective 1

Perform Effective Data Review and Analysis. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 4)

Part of the Data Engineering domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
10concepts
10%of the exam

Questions 16–20

  1. 16expert · hard

    A Splunk admin is integrating a new data source: firewall logs from a vendor that sends logs via syslog. The admin has configured the input, but the events show the `src_ip` field as the firewall's management IP for all events, and the `bytes` field is sometimes negative. The admin needs to determine whether the data is usable for security analysis. Which action should the admin take FIRST?

    Select an answer first
  2. 17application · medium

    A security analyst has correlated VPN logs with Active Directory account lockout events and found that a single user account was locked out 20 times in 10 minutes from different source IPs. What is the most actionable conclusion the analyst can draw?

    Select an answer first
  3. 18expert · hard

    A Splunk analyst is investigating a security incident and needs to analyze a large volume of network logs. The analyst wants to focus on traffic to a specific external IP address, but the logs contain many fields and the search is slow. Which approach best reduces the data volume and improves search performance?

    Select an answer first
  4. 19foundation · easy

    What is the main purpose of data visualization in Splunk?

    Select an answer first
  5. 20expert · hard

    A Splunk analyst needs to present a security dashboard to executives. The dashboard should show the trend of malware detections over the past 30 days and highlight the top 3 malware families. Which visualization approach best meets this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.