Splunk Certified Cybersecurity Defense Analyst Preparation Details
The Splunk Certified Cybersecurity Defense Analyst exam validates your ability to use Splunk Enterprise and Splunk Enterprise Security to detect, investigate, and respond to threats in a SOC. This guide maps every domain from the official test blueprint to the correlation search, risk framework, and SPL concepts you need to know. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills.
Splunk Certified Cybersecurity Defense Analyst Materials
| Coursera | SIEM Splunk Hands-On Guide Specialization |
| Udemy | Splunk Cybersecurity Defense Analyst Practice Tests |
| Whizlabs | Splunk Basics Training Course |
1.0 The Cyber Landscape, Frameworks, and Standards 10%
Topics Covered
1.1 Summarize the organization of a typical SOC and the tasks belonging to Analyst, Engineer and Architect roles.
What Is a SOC? Security Operations Centers Overview
Splunk Certified Cybersecurity Defense Analyst
1.2 Recognize common cyber industry controls, standards and frameworks and how Splunk incorporates those frameworks.
Set up controls using the InfoSec app for Splunk
Compliance Essentials for Splunk
1.3 Describe key security concepts surrounding information assurance including confidentiality, integrity and availability and basic risk management.
Using Splunk Enterprise Security to ensure GDPR compliance
Compliance Essentials for Splunk 2.1.0
Splunk Enterprise Security Features
2.0 Threat and Attack Types, Motivations, and Tactics 20%
Topics Covered
2.1 Recognize common types of attacks and attack vectors.
Accelerate Actionable Insights with Threat Investigation
Overview of threat intelligence in Splunk Enterprise Security
2.2 Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary.
Overview of threat intelligence in Splunk Enterprise Security
Supported types of threat intelligence in Splunk Enterprise Security
Accelerate Actionable Insights with Threat Investigation
2.3 Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis.
Overview of threat intelligence in Splunk Enterprise Security
Supported types of threat intelligence in Splunk Enterprise Security
Using threat intelligence in Splunk Enterprise Security
2.4 Outline the purpose and scope of annotations within Splunk Enterprise Security.
Identify annotations based risk objects in Splunk Enterprise Security
Optimizing correlation searches in Enterprise Security
How risk-based alerting works in Splunk Enterprise Security
2.5 Define tactics, techniques and procedures and how they are regarded in the industry.
How risk-based alerting works in Splunk Enterprise Security
Getting started with MITRE ATT&CK in Enterprise Security
Splunk Enterprise Security Features
3.0 Defenses, Data Sources, and SIEM Best Practices 20%
Topics Covered
3.1 Identify common types of cyber defense systems, analysis tools and the most useful data sources for threat analysis.
Accelerate Actionable Insights with Threat Investigation
Introduction to the dashboards available in Splunk ES
Splunk Enterprise Security Features
3.2 Describe SIEM best practices and basic operation concepts of Splunk Enterprise Security, including the interaction between CIM, Data Models and acceleration, Asset and Identity frameworks, and common CIM fields that may be used in investigations.
Introduction to the dashboards available in Splunk ES
Splunk Enterprise Security Features
3.3 Describe how Splunk Security Essentials and Splunk Enterprise Security can be used to assess data sources, including common sourcetypes for on-prem and cloud based deployments and how to find content for a given sourcetype.
Overview of Splunk Security Essentials
Review your content with the Security Content page
Getting started with Splunk Security Essentials
Track active content in Splunk Security Essentials
4.0 Investigation, Event Handling, Correlation, and Risk 20%
Topics Covered
4.1 Describe continuous monitoring and the five basic stages of investigation according to Splunk.
Overview of Incident Review in Splunk Enterprise Security
Accelerate Actionable Insights with Threat Investigation
4.2 Explain the different types of analyst performance metrics such as MTTR and dwell time.
Accelerate Actionable Insights with Threat Investigation
Overview of Incident Review in Splunk Enterprise Security
Splunk Enterprise Security Features
4.3 Demonstrate ability to recognize common event dispositions and correctly assign them.
Triage notables on Incident Review in Splunk Enterprise Security
Configure dispositions for findings in Splunk Enterprise Security
4.4 Define terms and aspects of Splunk Enterprise Security and their uses including SPL, Notable Event, Risk Notable, Adaptive Response Action, Risk Object, Contributing Events.
Splexicon: Adaptive response action
How risk-based alerting works in Splunk Enterprise Security
Take action on a notable on Incident Review in Splunk ES
4.5 Identify common built-in dashboards in Enterprise Security and the basic information they contain.
Introduction to the dashboards available in Splunk ES
Overview of Incident Review in Splunk Enterprise Security
4.6 Understand and explain the essentials of Risk Based Alerting, the Risk framework and creating correlation searches within Enterprise Security.
How risk-based alerting works in Splunk Enterprise Security
Analyze risk with risk-based alerting in Splunk ES
Part 2: Create a correlation search
Correlation search overview for Splunk Enterprise Security
5.0 SPL and Efficient Searching 20%
Topics Covered
5.1 Explain common SPL terms and how they can be used in security analysis, including TSTATS, TRANSACTION, FIRST/LAST, REX, EVAL, FOREACH, LOOKUP, and MAKERESULTS.
5.2 Give examples of Splunk best practices for composing efficient searches.
5.3 Identify SPL resources included within ES, Splunk Security Essentials, and Splunk Lantern.
Overview of Splunk Security Essentials
Review your content with the Security Content page
6.0 Threat Hunting and Remediation 10%
Topics Covered
6.1 Identify threat hunting techniques including configuration, modeling (anomalies), indicators, and behavioral analytics.
Optimizing correlation searches in Enterprise Security
Overview of Splunk Security Essentials
6.2 Define long tail analysis, outlier detection, and some common steps of hypothesis hunting with Splunk.
Accelerate Actionable Insights with Threat Investigation
6.3 Determine when to use adaptive response actions and configure them as needed.
Splexicon: Adaptive response action
Set up Adaptive Response actions in Splunk ES
Configure adaptive response actions for detections
Run adaptive response actions in Splunk ES
6.4 Explain the use of SOAR playbooks and list the basic ways they can be triggered from Enterprise Security.
Create a new playbook in Splunk SOAR (On-premises)
Create playbooks in Splunk SOAR
Configure automation rules to run playbooks on findings
Wrapping Up Splunk Certified Cybersecurity Defense Analyst
This guide walked through all six domains of the Splunk Certified Cybersecurity Defense Analyst blueprint, from SOC fundamentals through SPL, risk-based alerting, and threat hunting. Use the linked documentation to reinforce each objective before exam day. You can also explore more Splunk certification study guides on the Splunk category to keep building your skills. Have a question or tip? Leave a comment below.
Receive Updates on Splunk Certified Cybersecurity Defense Analyst Exam
Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.