Objective 2.3
Cybersecurity Defense EngineerUnderstand and create risk-based modifiers and detections
Objective 2.3 sits in Detection Engineering, which carries 40% of the Cybersecurity Defense Engineer exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An engineer asks what a risk score represents in Enterprise Security. Which description matches the documentation?
Correct.
Checked against help.splunk.com, August 2026Concept
Scoring an entity rather than an event is what lets separate detections add up. The number describes a machine or a person, not a moment.
Why B
Splunk documents a risk score as the single metric that shows the relative risk of an entity over time.
Source
Splunk Docs: Risk scoring in Splunk Enterprise Security, checked August 2026A risk score is the single metric that shows the relative risk of an entity over time.
Now you: objective 2.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An engineer asks what an entity means for risk scoring. Which definition does Splunk give?
Sample question 2 of 3
An engineer asks which two entity types Splunk Enterprise Security defines for risk. Which pair does the documentation name?
Sample question 3 of 3
An engineer knows an intermediate finding carries entity, entity_type and risk_score. Which further key field does Splunk name?
Full Cybersecurity Defense Engineer question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.