Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 2Objective 3

Understand and Create Risk-Based Modifiers and Detections. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 4)

Part of the Detection Engineering domain, which accounts for 40% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~12–20 in this domain), expect 2–4 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
6concepts
40%of the exam

Questions 16–20

  1. 16foundation · easy

    What is the primary purpose of a risk-based modifier in Splunk detection engineering?

    Select an answer first
  2. 17foundation · easy

    How does a risk score help prioritize detections in Splunk?

    Select an answer first
  3. 18application · medium

    An organization has a detection that flags 'multiple failed logons' and assigns a risk score of 10 to the 'user' risk object. The security team notices that failed logons from a specific 'source_ip' that is a known vulnerability scanner are generating noise. They want to reduce the risk score for events originating from that scanner. What is the best way to apply a risk-based modifier to achieve this?

    Select an answer first
  4. 19foundation · easy

    In Splunk, what does a risk-based modifier typically act upon?

    Select an answer first
  5. 20foundation · easy

    How do you apply a risk-based modifier to an existing detection in Splunk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.