Objective 1.1

Cybersecurity Defense Analyst

Summarize the organization of a typical SOC and the tasks belonging to Analyst, Engineer and Architect roles

Objective 1.1 sits in The Cyber Landscape, Frameworks, and Standards, which carries 10% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-1The Cyber Landscape, Frameworks, and Standards

An administrator is assigning Enterprise Security access. How many roles does Splunk document that the app adds to the platform defaults?

SixSix is well past the documented count.
TwoTwo would leave one of the documented user categories without a role.
FourFour is more than Splunk lists.
ThreeCorrect · your answerCorrect.

Correct.

Checked against help.splunk.com, August 2026

Concept

A small set of roles maps to the way a security team actually divides work: watching, working incidents, and running the platform. More roles would need more decisions than the split justifies.

Why D

Splunk documents that Enterprise Security adds three roles to the default roles provided by the Splunk platform.

Source

Splunk Enterprise Security adds three roles to the default roles provided by Splunk platform.

Splunk Docs: Configure users and roles for Splunk Enterprise Security, checked August 2026
#soc roles#enterprise security

Now you: objective 1.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-1The Cyber Landscape, Frameworks, and Standards

A team lead asks which Enterprise Security role suits someone who manages and investigates incidents and must edit notable events. Which does Splunk name?

Sample question 2 of 3

1-1The Cyber Landscape, Frameworks, and Standards

An analyst asks what the documented Security Director category does not do in Enterprise Security. What does Splunk say?

Sample question 3 of 3

1-1The Cyber Landscape, Frameworks, and Standards

An administrator wants to assign the ess_admin role directly to a person. What does Splunk document about that?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in The Cyber Landscape, Frameworks, and Standards