Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 2Objective 3

Understand and Create Risk-Based Modifiers and Detections. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 2)

Part of the Detection Engineering domain, which accounts for 40% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~12–20 in this domain), expect 2–4 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
6concepts
40%of the exam

Questions 6–10

  1. 6foundation · easy

    What is a key step in testing a risk-based detection in Splunk?

    Select an answer first
  2. 7application · medium

    A detection engineer is building a risk-based modifier that should only add risk when the event's 'dest' host is in a specific critical asset list. The engineer has a lookup file named 'critical_assets.csv' with a field 'dest'. What is the correct way to reference this lookup in the modifier's correlation search?

    Select an answer first
  3. 8expert · medium

    A detection engineer is tuning a detection that flags 'suspicious PowerShell' activity. The detection currently assigns a risk score of 20 to the 'user' risk object. The engineer wants to increase the score by 30 when the user is a 'domain_admin' and decrease it by 10 when the user is a 'standard_user'. A 'domain_admin' user triggers the detection. What is the final risk score for this user?

    Select an answer first
  4. 9foundation · easy

    When creating a risk-based modifier in Splunk, what must you specify?

    Select an answer first
  5. 10foundation · easy

    What should you check when validating a risk-based detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.