Objective 4.2
Cybersecurity Defense AnalystExplain the different types of analyst performance metrics such as MTTR and dwell time
Objective 4.2 sits in Investigation, Event Handling, Correlation, and Risk, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A SOC manager wants the average time in minutes taken to prioritise a notable for investigation. Which SOC Operations panel reports it?
Correct.
Checked against help.splunk.com, August 2026Concept
Triage time and resolution time measure different halves of the same queue. One says how fast work is picked up, the other how fast it is finished, and a team can be good at one and poor at the other.
Why B
Splunk documents Mean Time to Triage as the average time in minutes to triage or prioritise the investigation of a notable.
Source
Splunk Docs: SOC Operations dashboard, checked August 2026Displays the average time (in minutes) to triage or prioritize the investigation of a notable over the duration of a specified time period.
Now you: objective 4.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An analyst asks what Mean Time to Resolution measures on the SOC Operations dashboard. Which description matches the documentation?
Sample question 2 of 3
A team lead wants to see how many notables each owner has closed against how many remain open. Which SOC Operations panel gives that comparison?
Sample question 3 of 3
An analyst notices that notables are being worked but many sit unowned. Which SOC Operations panel is documented to compare assigned against unassigned notables over time?
Full Cybersecurity Defense Analyst question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Investigation, Event Handling, Correlation, and Risk
- 4.1 Describe continuous monitoring and the five basic stages of investigation according to Splunk
- 4.3 Demonstrate ability to recognize common event dispositions and correctly assign them
- 4.4 Define terms and aspects of Splunk Enterprise Security and their uses including SPL, Notable Event, Risk Notable, Adaptive Response Action, Risk Object, Contributing Events
- 4.5 Identify common built-in dashboards in Enterprise Security and the basic information they contain
- 4.6 Understand and explain the essentials of Risk Based Alerting, the Risk framework and creating correlation searches within Enterprise Security