Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 1Objective 1

Develop and Implement Customized Threat Intelligence Strategies, Including Both Open Source and Commercial Intelligence Providers. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Advanced Threat Intelligence and Analysis domain, which accounts for 5% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
5%of the exam

Questions 16–20

  1. 16expert · hard

    A multinational corporation is developing its threat intelligence strategy. The company has a high risk of industrial espionage and targeted attacks. The CISO wants to invest in a commercial intelligence provider that offers strategic reports on threat actor groups and their TTPs. However, the SOC manager argues that the budget should be spent on more tactical feeds with IoCs for immediate detection. The company has a limited budget and can only afford one provider. Which approach best balances the strategic and tactical needs of the organization?

    Select an answer first
  2. 17foundation · easy

    Which of the following is an example of an open source threat intelligence source?

    Select an answer first
  3. 18application · medium

    A small e-commerce company wants to use OSINT to protect its web applications. The team has identified several free feeds that contain indicators of compromise, such as malicious IPs and URLs. They are concerned about the reliability of these feeds and want to ensure they are using high-quality data. What is the most important step to take when integrating these OSINT feeds into their security monitoring?

    Select an answer first
  4. 19application · medium

    A mid-sized healthcare organization wants to operationalize threat intelligence to improve its detection capabilities. The security team has a Splunk environment and has access to several OSINT feeds, including a list of known malicious C2 domains. The team's goal is to detect compromised hosts inside the network that are communicating with these C2 domains. What is the most effective way to operationalize this intelligence in Splunk?

    Select an answer first
  5. 20foundation · easy

    What is the correct order of the threat intelligence lifecycle phases?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.