Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 2

Identify Data Sources Critical to Cybersecurity Operations, Such as Event Sources, Identity Directories, Asset Management Systems, and Vulnerability - Assessments. This Can Include Non-Security Data Sources, Eg. Observability Tools. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A security team is responding to a ransomware incident and needs to quickly identify all endpoints that are missing a critical security patch. They have access to vulnerability scanner reports and a CMDB. Which approach would be most efficient?

    Select an answer first
  2. 12foundation · easy

    What type of data do identity directories like Active Directory and LDAP provide that is essential for security investigations?

    Select an answer first
  3. 13application · medium

    A security operations center is overwhelmed with alerts and needs to reduce false positives. They want to enrich authentication events with additional context to determine if a login is legitimate. Which data source would provide the most useful enrichment?

    Select an answer first
  4. 14foundation · easy

    Which of the following is an example of non-security data from observability tools that could help correlate with security events?

    Select an answer first
  5. 15expert · hard

    A security team is investigating a potential insider threat where an employee may have accessed sensitive files outside of normal working hours. They have access to Active Directory logs, firewall logs, and a CMDB. Which data source would provide the most direct evidence of the employee's actions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.