Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 2Objective 3

Understand and Create Risk-Based Modifiers and Detections. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 5)

Part of the Detection Engineering domain, which accounts for 40% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~12–20 in this domain), expect 2–4 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
6concepts
40%of the exam

Questions 21–23

  1. 21application · medium

    A detection engineer has just created a new risk-based modifier that adds 30 to the risk score for a 'user' when a specific threat-intel match occurs. Before deploying it to production, the engineer wants to validate that the modifier behaves as intended. What is the most appropriate validation step?

    Select an answer first
  2. 22expert · medium

    A security team has a detection that assigns a risk score of 25 to the 'user' risk object for 'impossible travel' events. They also have a risk-based modifier that adds 15 to the risk score when the user is a 'vip' and subtracts 10 when the user is a 'contractor'. A 'vip' user triggers the detection. What is the final risk score for this user from this detection?

    Select an answer first
  3. 23application · medium

    A detection engineer is creating a risk-based modifier that should increase the risk score for a 'user' risk object by 20 when the user is a member of the 'Domain Admins' group, and by 5 otherwise. The engineer has already built the lookup that maps users to their group membership. What is the correct way to implement this in the risk-based modifier?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.