Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 6

Describe the Value of Data Normalization in Order to Support Integration into Cybersecurity Defense Programs, Such as Security Monitoring and Threat Hunting, E.g. with CIM, CEF. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    A threat hunter is looking for signs of data exfiltration by searching for large outbound transfers across firewall, proxy, and cloud storage logs. The data is normalized to CIM. Which field would the hunter use to filter for outbound traffic in a single search?

    Select an answer first
  2. 12expert · hard

    A SOC has normalized their endpoint and network data to CIM. They now want to create a detection that identifies when a host communicates with a known-bad IP address. The detection should work across both data sources. What is the most efficient way to implement this detection?

    Select an answer first
  3. 13foundation · easy

    What is the primary purpose of the Splunk Common Information Model (CIM)?

    Select an answer first
  4. 14foundation · easy

    Why is a unified view of data important for threat hunting?

    Select an answer first
  5. 15expert · hard

    A security engineer is configuring a legacy device to send CEF events to a SIEM. The device does not support the standard CEF header fields for source and destination IPs, but it can send custom extension fields. The SIEM expects the source IP in the CEF 'src' header field. What is the best approach to ensure the SIEM correctly identifies the source IP?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.