Objective 4.1

Cybersecurity Defense Analyst

Describe continuous monitoring and the five basic stages of investigation according to Splunk

Objective 4.1 sits in Investigation, Event Handling, Correlation, and Risk, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

4-1Investigation, Event Handling, Correlation, and Risk

A reviewing analyst picks up a newly assigned notable event and starts work on it. Which status does Splunk document that the analyst sets at that point?

ClosedClosed is set by the final analyst after validation.
ResolvedResolved comes after the cause is addressed.
In ProgressCorrect · your answerCorrect.
PendingPending is a status on the Incident Review pie chart, not the one set here.

Correct.

Checked against help.splunk.com, August 2026

Concept

Status is the shared signal on a queue. It tells everyone else whether an item is waiting, being worked or finished, so the transition has to happen when work starts rather than when it ends.

Why C

Splunk documents that the reviewing analyst moves the event from New to In Progress and then begins investigating its cause.

Source

The reviewing analyst updates the status of the event from New to In Progress , and begins investigating the cause of the notable event.

Splunk Docs: Overview of Incident Review in Splunk Enterprise Security, checked August 2026
#incident review#workflow

Now you: objective 4.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

4-1Investigation, Event Handling, Correlation, and Risk

An analyst has addressed the cause of a notable event and escalated the remaining remediation work. Splunk's documented workflow says the event then goes where next?

Sample question 2 of 3

4-1Investigation, Event Handling, Correlation, and Risk

An analyst is deciding where to record the research done on a notable event so the next reviewer can follow it. Which field does Splunk name for that?

Sample question 3 of 3

4-1Investigation, Event Handling, Correlation, and Risk

A team lead asks what an analyst should do when a notable event turns out to need lengthier work than a single review pass. Which documented option applies?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Investigation, Event Handling, Correlation, and Risk