You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Splunk Certified Cybersecurity Defense Engineer certification validates your ability to optimize SOC workflows using Splunk Enterprise Security and Splunk SOAR. You'll learn to craft and tune effective detections, incorporate threat intelligence, and build automations that follow industry best practices. This credential is for security professionals ready to advance from analyst to defense engineering roles.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Splunk Certified Cybersecurity Defense Engineer certification establishes an intermediate-level standard for professionals who use Splunk Enterprise, Enterprise Security, and Splunk SOAR to defend security operations centers (SOCs). It validates your ability to create and tune detections, incorporate risk, develop and follow security processes, and efficiently automate standard operating procedures.
Earning this certification demonstrates that you can move beyond day-to-day monitoring into engineering: designing detection logic, integrating threat intelligence, and building SOAR playbooks that reduce manual effort. It is a career milestone for SOC analysts aiming to become defense engineers and for cybersecurity professionals who want to prove their operational expertise with Splunk security products.
This certification is for Splunk Certified Cybersecurity Defense Analysts who want to grow into the Defense Engineering career path. It is also suited to SOC detection engineers and cybersecurity professionals who use Splunk Enterprise Security and Splunk SOAR to optimize detection and automation in a SOC environment. Candidates typically have hands-on experience with Splunk security tools and are comfortable analyzing security vulnerabilities and threats, developing detections, and automating standard operating procedures.
Splunk recommends that candidates hold the Splunk Certified Cybersecurity Defense Analyst certification and have practical experience with Splunk Enterprise Security and Splunk SOAR. Experience as a Splunk Certified Cybersecurity Defense Analyst or equivalent SOC analyst role; Hands-on use of Splunk Enterprise Security for detection and monitoring; Hands-on use of Splunk SOAR for automation and orchestration; Understanding of security operations workflows and standard operating procedures
Every domain and objective Splunk measures, with the weight they carry on the exam.
The official Splunk exam outline · checked 30 July 2026 · See the source
Everything Splunk publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path Splunk lays out, how the credential is kept, and where to book.
Step-by-step path to Splunk Certified Cybersecurity Defense Engineer
Splunk certifications must be renewed every three years. You can renew by pursuing additional certifications, completing continuing education courses, or re-taking the certification exam. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. Splunk maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, Splunk’s authorized testing partner.
Schedule your examVisit the official Splunk certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe Engineer certification is the next step after the Analyst certification. It is designed for Splunk Certified Cybersecurity Defense Analysts who want to grow into the Defense Engineering career path, focusing on creating and tuning detections, incorporating threat intelligence, and automating SOC workflows.
No, the Analyst certification is not a mandatory prerequisite. However, Splunk explicitly recommends it as the intended pathway, and the exam is designed for candidates who already hold that credential.
This certification is aimed at SOC Detection Engineers and cybersecurity professionals who want to advance from SOC analyst roles into defense engineering. It validates skills critical to optimizing detection and automation in a SOC environment.
Yes. Splunk's recertification policy allows you to renew your certification by pursuing additional certifications, completing continuing education courses, or re-taking the certification exam every three years.
The exam format is 60 multiple choice questions. There is no hands-on lab component mentioned in the official exam details.
The exam is delivered by Pearson VUE, which offers online and onsite testing options. You can schedule your exam through the Pearson VUE website after registering.
Every domain, every objective, and every concept Splunk measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official Splunk exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
34 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 19 objectives, 140 concepts written under them, and free questions against every one. When Splunk changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.