Exam objectives
Cybersecurity Defense AnalystSplunk Certified Cybersecurity Defense Analyst exam objectives
The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.
Titles and weightings from the official objectives. Splunk exam page ↗
The Cyber Landscape, Frameworks, and Standards
10%of exam- 1.1 Summarize the organization of a typical SOC and the tasks belonging to Analyst, Engineer and Architect rolesPractice
- 1.2 Recognize common cyber industry controls, standards and frameworks and how Splunk incorporates those frameworksPractice
- 1.3 Describe key security concepts surrounding information assurance including confidentiality, integrity and availability and basic risk managementPractice
Threat and Attack Types, Motivations, and Tactics
20%of exam- 2.1 Recognize common types of attacks and attack vectorsPractice
- 2.2 Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversaryPractice
- 2.3 Identify the common tiers of Threat Intelligence and how they might be applied to threat analysisPractice
- 2.4 Outline the purpose and scope of annotations within Splunk Enterprise SecurityPractice
- 2.5 Define tactics, techniques and procedures and how they are regarded in the industryPractice
Defenses, Data Sources, and SIEM Best Practices
20%of exam- 3.1 Identify common types of cyber defense systems, analysis tools and the most useful data sources for threat analysisPractice
- 3.2 Describe SIEM best practices and basic operation concepts of Splunk Enterprise Security, including the interaction between CIM, Data Models and acceleration, Asset and Identity frameworks, and common CIM fields that may be used in investigationsPractice
- 3.3 Describe how Splunk Security Essentials and Splunk Enterprise Security can be used to assess data sources, including common sourcetypes for on-prem and cloud based deployments and how to find content for a given sourcetypePractice
Investigation, Event Handling, Correlation, and Risk
20%of exam- 4.1 Describe continuous monitoring and the five basic stages of investigation according to SplunkPractice
- 4.2 Explain the different types of analyst performance metrics such as MTTR and dwell timePractice
- 4.3 Demonstrate ability to recognize common event dispositions and correctly assign themPractice
- 4.4 Define terms and aspects of Splunk Enterprise Security and their uses including SPL, Notable Event, Risk Notable, Adaptive Response Action, Risk Object, Contributing EventsPractice
- 4.5 Identify common built-in dashboards in Enterprise Security and the basic information they containPractice
- 4.6 Understand and explain the essentials of Risk Based Alerting, the Risk framework and creating correlation searches within Enterprise SecurityPractice
SPL and Efficient Searching
20%of exam- 5.1 Explain common SPL terms and how they can be used in security analysis, including TSTATS, TRANSACTION, FIRST/LAST, REX, EVAL, FOREACH, LOOKUP, and MAKERESULTSPractice
- 5.2 Give examples of Splunk best practices for composing efficient searchesPractice
- 5.3 Identify SPL resources included within ES, Splunk Security Essentials, and Splunk LanternPractice
Threat Hunting and Remediation
10%of exam- 6.1 Identify threat hunting techniques including configuration, modeling (anomalies), indicators, and behavioral analyticsPractice
- 6.2 Define long tail analysis, outlier detection, and some common steps of hypothesis hunting with SplunkPractice
- 6.3 Determine when to use adaptive response actions and configure them as neededPractice
- 6.4 Explain the use of SOAR playbooks and list the basic ways they can be triggered from Enterprise SecurityPractice
Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.
Keep reading
Cybersecurity Defense Analyst practice questions
Free sample questions with the full explanation on every answer.
Free Cybersecurity Defense Analyst practice test
Ten real questions, playable now. No account, no card.
Cybersecurity Defense Analyst passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is Cybersecurity Defense Analyst?
An honest difficulty read from the format, the clock and the weights.