
SplunkCertified Cybersecurity Defense Engineer
Domain 3Objective 2
Use Common Methodologies for Risk and Detection Prioritization. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 2)
Part of the Building Effective Security Processes and Programs domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
20%of the exam
Questions 6–10
- 6
A security team has implemented a set of detection use cases based on an initial risk assessment. Six months later, the organization has adopted new cloud services and the threat landscape has shifted. What should the team do to ensure their detection priorities remain effective?
Select an answer first - 7
A security operations team is deciding which detection use cases to implement. They have limited engineering resources and want to focus on detections that address the most relevant threats to their industry. They have access to threat intelligence indicating that ransomware operators are actively targeting their sector. Which detection use case should be prioritized?
Select an answer first - 8
A security analyst is reviewing a series of alerts and wants to understand the adversary's progression through the attack lifecycle. They have observed initial access via a phishing email, followed by command and control traffic. Using MITRE ATT&CK, which tactic should the analyst look for next to anticipate the adversary's likely next move?
Select an answer first - 9
A company has identified a risk of data exfiltration from its cloud storage. The risk is assessed as high likelihood and high impact. The company has a limited budget and must choose a risk treatment option. They are considering purchasing cyber insurance, implementing data loss prevention (DLP) controls, or accepting the risk. Which option is the most appropriate risk treatment?
Select an answer first - 10
Which asset classification label would be most appropriate for a database containing customer payment card information that is subject to regulatory requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.