Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 2Objective 3

Understand and Create Risk-Based Modifiers and Detections. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 3)

Part of the Detection Engineering domain, which accounts for 40% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~12–20 in this domain), expect 2–4 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
6concepts
40%of the exam

Questions 11–15

  1. 11expert · medium

    A detection engineer has a detection that assigns a risk score of 10 to the 'user' risk object for 'failed logon' events. The engineer wants to add a modifier that increases the score by 20 when the user is a 'domain_admin' and decreases it by 5 when the user is a 'standard_user'. A 'standard_user' triggers the detection. What is the final risk score for this user?

    Select an answer first
  2. 12application · medium

    A detection for 'possible credential dumping' is generating false positives for a specific set of legitimate administrative tools. The detection engineer wants to reduce the risk score contribution for these tools without disabling the detection entirely. The risk object is 'user'. What is the most effective way to achieve this?

    Select an answer first
  3. 13foundation · easy

    What is a common use of risk-based modifiers in tuning detections?

    Select an answer first
  4. 14application · easy

    A SOC manager is reviewing the risk scores for a 'user' who triggered two detections: one for 'credential theft' with a score of 40 and one for 'lateral movement' with a score of 30. The manager wants to know the user's total risk score to decide if they should be escalated. What is the total risk score for this user?

    Select an answer first
  5. 15foundation · easy

    What is the effect of applying a risk-based modifier to a detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.