Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 1Objective 1

Develop and Implement Customized Threat Intelligence Strategies, Including Both Open Source and Commercial Intelligence Providers. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)

Part of the Advanced Threat Intelligence and Analysis domain, which accounts for 5% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
5%of the exam

Questions 6–10

  1. 6expert · hard

    A large enterprise has a mature threat intelligence program. The team collects data from multiple commercial and OSINT sources, processes it into a standardized format, and disseminates it to various teams (SOC, IR, threat hunting). Recently, the SOC has complained that the intelligence is often outdated by the time they receive it, and the threat hunting team says the data is too generic to be useful. The team lead suspects the issue is in the processing and analysis phase of the intelligence lifecycle. Which of the following changes would most directly address the SOC's and threat hunting team's complaints?

    Select an answer first
  2. 7foundation · easy

    What is the primary purpose of a threat intelligence strategy in an organization?

    Select an answer first
  3. 8foundation · easy

    Which of the following is an example of customizing a threat intelligence source?

    Select an answer first
  4. 9application · medium

    A university's security team is setting up a threat intelligence program. They have access to a variety of OSINT sources, including public malware sandbox reports, domain registries, and social media monitoring. The team's primary use case is to detect phishing campaigns targeting students and staff. They want to create a customized feed that is relevant to their environment. What is the most effective way to customize their OSINT collection to meet this specific use case?

    Select an answer first
  5. 10expert · hard

    A large retail chain is developing a threat intelligence strategy. The company has a high volume of point-of-sale (POS) malware incidents. The security team has a commercial feed that provides indicators of POS malware, but the feed is expensive and the team is considering whether to continue the subscription. The team also has access to a free OSINT feed that includes some POS malware indicators. The CISO wants to ensure the strategy is cost-effective while maintaining detection capability. What is the most important factor to consider in this decision?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.