
SplunkCertified Cybersecurity Defense Architect
Domain 1Objective 1
Develop and Implement Customized Threat Intelligence Strategies, Including Both Open Source and Commercial Intelligence Providers. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)
Part of the Advanced Threat Intelligence and Analysis domain, which accounts for 5% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
5%of the exam
Questions 11–15
- 11
A non-profit organization has a small security team and wants to start using OSINT to improve its security posture. The team has identified several free feeds but is concerned about the time required to manage them. They want to automate the collection and processing of these feeds as much as possible. What is the most effective way to automate the management of OSINT feeds in their Splunk environment?
Select an answer first - 12
A security operations center is reviewing its threat intelligence lifecycle. The team has a process for collecting data from various sources, but the analysis phase is often delayed because analysts are spending too much time on manual data processing. The team wants to improve the efficiency of the processing and analysis phase. Which of the following actions would be most effective?
Select an answer first - 13
What is the primary goal of operationalizing threat intelligence?
Select an answer first - 14
What is a key consideration when comparing the cost of commercial threat intelligence providers?
Select an answer first - 15
A financial services firm is evaluating commercial threat intelligence providers. The firm's key requirements are: (1) coverage of financial-sector threats, (2) integration with their Splunk SIEM, and (3) a cost that fits their budget. The team has shortlisted three providers. Provider X has excellent coverage but no native Splunk integration. Provider Y has a Splunk app but its coverage is more general. Provider Z is cheap but has limited coverage of financial threats. Which provider should the firm choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.