Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 1Objective 3

Understand and Apply Splunk Methods of Data Normalization. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 3)

Part of the Data Engineering domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 11–15

  1. 11foundation · easy

    Which technique would you use to create a new CIM-compliant field that combines two raw fields, such as creating 'src_ip' from 'client_ip' and 'source_address' when one or the other is present?

    Select an answer first
  2. 12application · medium

    An organization ingests Windows Security Event logs (Event ID 4624 for successful logons) and sudo logs from Linux servers. The team wants both sources to populate the Authentication data model so that the `user`, `src`, and `action` fields are normalized. The Windows events already have `user` and `src` mapped via aliases, but the Linux sudo events do not have the required CIM tags. What must the team do to ensure the Linux events are properly categorized in the Authentication data model?

    Select an answer first
  3. 13foundation · easy

    What is the recommended way to add an organization-specific field to a CIM data model without breaking normalization standards?

    Select an answer first
  4. 14application · medium

    A security team ingests firewall logs where the source IP field is named `src_ip` and the destination IP is `dst_ip`. They also ingest VPN logs where the same fields are named `SourceAddress` and `DestAddress`. The team wants both datasets to populate the `src` and `dest` fields in the Network Traffic CIM data model so that a single correlation search can work across both sources. The team must avoid modifying the raw data. Which configuration should the team apply?

    Select an answer first
  5. 15expert · hard

    A security engineer is validating CIM compliance for a new endpoint data source. The CIM Validation tool reports that events are tagged with `endpoint` but the `user` field is missing. The raw events contain a `username` field. The engineer adds a field alias mapping `username` to `user`. After refreshing the data model, the validation still shows `user` as missing. What is the most likely reason?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.