Objective 2.3

Cybersecurity Defense Engineer

Understand and create risk-based modifiers and detections

Objective 2.3 sits in Detection Engineering, which carries 40% of the Cybersecurity Defense Engineer exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-3Detection Engineering

An engineer asks what a risk score represents in Enterprise Security. Which description matches the documentation?

Severity of a single eventSeverity describes one finding rather than a running total.
Relative risk of an entityCorrect · your answerCorrect.
Confidence in a detection ruleConfidence is an annotation on a detection.
Impact rating of an assetAsset priority is held in the asset and identity framework.

Correct.

Checked against help.splunk.com, August 2026

Concept

Scoring an entity rather than an event is what lets separate detections add up. The number describes a machine or a person, not a moment.

Why B

Splunk documents a risk score as the single metric that shows the relative risk of an entity over time.

Source

A risk score is the single metric that shows the relative risk of an entity over time.

Splunk Docs: Risk scoring in Splunk Enterprise Security, checked August 2026
#risk scoring#entities

Now you: objective 2.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-3Detection Engineering

An engineer asks what an entity means for risk scoring. Which definition does Splunk give?

Sample question 2 of 3

2-3Detection Engineering

An engineer asks which two entity types Splunk Enterprise Security defines for risk. Which pair does the documentation name?

Sample question 3 of 3

2-3Detection Engineering

An engineer knows an intermediate finding carries entity, entity_type and risk_score. Which further key field does Splunk name?

Full Cybersecurity Defense Engineer question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Detection Engineering