Splunk Certified Cybersecurity Defense Analyst Practice Test

169 प्रश्न उपलब्ध

Splunk Certified Cybersecurity Defense Analyst के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
66 परीक्षा प्रश्न
1 घंटा 15 मिनट समय सीमा
आपका अभ्यास
169 अभ्यास सवाल
2 घंटे 49 मिनट अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
प्रश्न बैंक 169 आधिकारिक उद्देश्यों के विरुद्ध जाँचे गए अभ्यास प्रश्न.
Splunk169 अभ्यास प्रश्न

परीक्षा का परिचय और विवरण

Splunk Certified Cybersecurity Defense Analyst exam covering SOC workflows, threat detection, incident response, and security analytics with Splunk. Administered by Splunk. Key domains include Defenses, Data Sources, and SIEM Best Practices, Investigation, Event Handling, Correlation, and Risk, SPL and Efficient Searching and Threat and Attack Types, Motivations, and Tactics. The exam consists of 66 questions over 75 minutes.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

Threat and Attack Types, Motivations, and Tactics

A public web server is repeatedly probed for one CVE, then a web shell-like file appears and outbound connections begin. Which attack vector is most likely?

Threat and Attack Types, Motivations, and Tactics

Endpoint logs show mshta launching script content from a user profile after a phishing message, followed by outbound beaconing. Which description is most accurate?

SPL and Efficient Searching

A search needs unique destination count per user and total event count per user. Which stats functions fit?

Investigation, Event Handling, Correlation, and Risk

A risk analysis view shows 12 contributing events for user jlee over four hours. What should the analyst do first?

Defenses, Data Sources, and SIEM Best Practices

During identity triage, user appears as email in one source and sAMAccountName in another. Which control improves correlation?

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

पढ़ाई की योजना बनाने के लिए प्रकाशित डोमेन भार का उपयोग करें। अभ्यास के परिणाम आपके सर्टिफिकेशन परीक्षा के स्कोर का अनुमान नहीं हैं।

01Defenses, Data Sources, and SIEM Best Practices

20%

विषय

  • Identify common types of cyber defense systems, analysis tools and the most useful data sources for threat analysis.
  • Describe SIEM best practices and basic operation concepts of Splunk Enterprise Security, including the interaction between CIM, Data Models and acceleration, Asset and Identity frameworks, and common CIM fields that may be used in investigations.
  • Describe how Splunk Security Essentials and Splunk Enterprise Security can be used to assess data sources, including common sourcetypes for on-prem and cloud based deployments and how to find content for a given sourcetype.

सीखने के उद्देश्य

  • Identify common types of cyber defense systems, analysis tools and the most useful data sources for threat analysis.
  • Describe SIEM best practices and basic operation concepts of Splunk Enterprise Security, including the interaction between CIM, Data Models and acceleration, Asset and Identity frameworks, and common CIM fields that may be used in investigations.
  • Describe how Splunk Security Essentials and Splunk Enterprise Security can be used to assess data sources, including common sourcetypes for on-prem and cloud based deployments and how to find content for a given sourcetype.

02Investigation, Event Handling, Correlation, and Risk

20%

विषय

  • Describe continuous monitoring and the five basic stages of investigation according to Splunk.
  • Explain the different types of analyst performance metrics such as MTTR and dwell time.
  • Demonstrate ability to recognize common event dispositions and correctly assign them.
  • Define terms and aspects of Splunk Enterprise Security and their uses including SPL, Notable Event, Risk Notable, Adaptive Response Action, Risk Object, Contributing Events.
  • Identify common built-in dashboards in Enterprise Security and the basic information they contain.
  • Understand and explain the essentials of Risk Based Alerting, the Risk framework and creating correlation searches within Enterprise Security.

सीखने के उद्देश्य

  • Describe continuous monitoring and the five basic stages of investigation according to Splunk.
  • Explain the different types of analyst performance metrics such as MTTR and dwell time.
  • Demonstrate ability to recognize common event dispositions and correctly assign them.
  • Define terms and aspects of Splunk Enterprise Security and their uses including SPL, Notable Event, Risk Notable, Adaptive Response Action, Risk Object, Contributing Events.
  • Identify common built-in dashboards in Enterprise Security and the basic information they contain.
  • Understand and explain the essentials of Risk Based Alerting, the Risk framework and creating correlation searches within Enterprise Security.

03SPL and Efficient Searching

20%

विषय

  • Explain common SPL terms and how they can be used in security analysis, including TSTATS, TRANSACTION, FIRST/LAST, REX, EVAL, FOREACH, LOOKUP, and MAKERESULTS.
  • Give examples of Splunk best practices for composing efficient searches.
  • Identify SPL resources included within ES, Splunk Security Essentials, and Splunk Lantern.

सीखने के उद्देश्य

  • Explain common SPL terms and how they can be used in security analysis, including TSTATS, TRANSACTION, FIRST/LAST, REX, EVAL, FOREACH, LOOKUP, and MAKERESULTS.
  • Give examples of Splunk best practices for composing efficient searches.
  • Identify SPL resources included within ES, Splunk Security Essentials, and Splunk Lantern.

04Threat and Attack Types, Motivations, and Tactics

20%

विषय

  • Recognize common types of attacks and attack vectors.
  • Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary.
  • Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis.
  • Outline the purpose and scope of annotations within Splunk Enterprise Security.
  • Define tactics, techniques and procedures and how they are regarded in the industry.

सीखने के उद्देश्य

  • Recognize common types of attacks and attack vectors.
  • Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary.
  • Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis.
  • Outline the purpose and scope of annotations within Splunk Enterprise Security.
  • Define tactics, techniques and procedures and how they are regarded in the industry.

05The Cyber Landscape, Frameworks, and Standards

10%

विषय

  • Summarize the organization of a typical SOC and the tasks belonging to Analyst, Engineer and Architect roles.
  • Recognize common cyber industry controls, standards and frameworks and how Splunk incorporates those frameworks.
  • Describe key security concepts surrounding information assurance including confidentiality, integrity and availability and basic risk management.

सीखने के उद्देश्य

  • Summarize the organization of a typical SOC and the tasks belonging to Analyst, Engineer and Architect roles.
  • Recognize common cyber industry controls, standards and frameworks and how Splunk incorporates those frameworks.
  • Describe key security concepts surrounding information assurance including confidentiality, integrity and availability and basic risk management.

06Threat Hunting and Remediation

10%

विषय

  • Identify threat hunting techniques including configuration, modeling (anomalies), indicators, and behavioral analytics.
  • Define long tail analysis, outlier detection, and some common steps of hypothesis hunting with Splunk.
  • Determine when to use adaptive response actions and configure them as needed.
  • Explain the use of SOAR playbooks and list the basic ways they can be triggered from Enterprise Security.

सीखने के उद्देश्य

  • Identify threat hunting techniques including configuration, modeling (anomalies), indicators, and behavioral analytics.
  • Define long tail analysis, outlier detection, and some common steps of hypothesis hunting with Splunk.
  • Determine when to use adaptive response actions and configure them as needed.
  • Explain the use of SOAR playbooks and list the basic ways they can be triggered from Enterprise Security.

परीक्षा विवरण 1 घंटा 15 मिनट

विक्रेता Splunk
समय सीमा 1 घंटा 15 मिनट
परीक्षा प्रश्न 66

अक्सर पूछे जाने वाले प्रश्न

इस परीक्षा को देने से पहले कितने हाथों-हाथ Splunk ES अनुभव की सिफारिश की जाती है?

क्या परीक्षा बहुविकल्पीय है, या इसमें व्यावहारिक कार्य शामिल हैं?

मेरे अध्ययन पर ध्यान केंद्रित करने के लिए सबसे महत्वपूर्ण क्षेत्र कौन सा है?

मुझे आधिकारिक परीक्षा ब्लूप्रिंट का उपयोग कैसे करना चाहिए?

क्या ऐसे विशिष्ट डेटा स्रोत या उपयोग के मामले हैं जिन्हें मुझे प्राथमिकता देनी चाहिए?