
SplunkCertified Cybersecurity Defense Engineer
Domain 1Objective 3
Understand and Apply Splunk Methods of Data Normalization. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 4)
Part of the Data Engineering domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
10%of the exam
Questions 16–20
- 16
A security team ingests both firewall and proxy logs. The firewall logs are tagged with `network` and `communicate`, and the proxy logs are tagged with `web`. The team wants to run a search that uses the Network Traffic data model to analyze both firewall and proxy connections. The proxy logs have the required fields aliased. However, the Network Traffic data model only returns firewall events. What is the most likely cause?
Select an answer first - 17
A security team is ingesting DNS logs from multiple sources. Each source uses different field names for the query (e.g., `query`, `qname`, `domain`). The team wants to normalize these to the `query` field in the Network Resolution data model. They have already created field aliases. What is the next step to ensure the data model populates correctly?
Select an answer first - 18
An organization wants to track a custom field `risk_level` in their Endpoint data model. This field is populated by a threat intelligence feed and is not part of the standard CIM. The team wants to keep using the standard Endpoint data model for their existing dashboards. What is the best approach?
Select an answer first - 19
What is the purpose of event tagging in the context of CIM normalization?
Select an answer first - 20
Which of the following is a standard field defined in the CIM Network Traffic data model?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.