Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 1Objective 3

Understand and Apply Splunk Methods of Data Normalization. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 5)

Part of the Data Engineering domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 21–25

  1. 21application · medium

    A security operations center needs to track a custom field, `threat_score`, that is present in their threat intelligence feeds. This field is not part of any standard CIM data model. The team wants to include `threat_score` in the Intrusion Detection data model so that their existing CIM-based dashboards can display it alongside standard fields. What is the recommended approach?

    Select an answer first
  2. 22application · medium

    A team ingests firewall logs with a field named `policy_id` that they want to keep as-is for their own reporting, but they also need it to populate the `rule` field in the Network Traffic data model. They do not want to change the raw data. What is the best way to achieve this?

    Select an answer first
  3. 23application · medium

    A company ingests network flows from two different vendors. Vendor A uses `source_ip` and `dest_ip`, while Vendor B uses `src_addr` and `dst_addr`. The security team wants to run a single search that counts connections by source IP across both vendors. They have already created field aliases mapping both raw field sets to `src` and `dest`. What additional step is required to ensure the data is fully CIM-compliant for the Network Traffic data model?

    Select an answer first
  4. 24expert · hard

    A SOC analyst is troubleshooting why the CIM Validation tool reports that events are tagged with `authentication` but the `src` field is not populated. The raw events contain a field named `Source_IP`. The analyst adds a field alias mapping `Source_IP` to `src` in props.conf and transforms.conf. After refreshing, the validation still shows `src` as missing. What is the most likely cause?

    Select an answer first
  5. 25application · medium

    A SOC analyst is building a dashboard to visualize failed and successful authentication attempts. They want to use the Authentication data model. The data comes from Windows Event Logs and Linux sudo logs. The Windows events are already tagged and normalized. The Linux events have the `user` and `action` fields aliased but are not appearing in the data model. What is the most likely reason?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.