Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 2

Identify Data Sources Critical to Cybersecurity Operations, Such as Event Sources, Identity Directories, Asset Management Systems, and Vulnerability - Assessments. This Can Include Non-Security Data Sources, Eg. Observability Tools. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A security operations team is deploying a new SIEM and must prioritize which event sources to ingest first. They have limited ingestion capacity and need to maximize visibility into network-based threats. Which data source should be prioritized?

    Select an answer first
  2. 17expert · hard

    A security analyst is investigating a distributed denial-of-service (DDoS) attack that targeted a web application. The analyst has access to firewall logs, infrastructure monitoring metrics, and APM traces. Which data source would be most helpful to understand the impact on application performance?

    Select an answer first
  3. 18application · medium

    A security analyst is investigating a potential account compromise and needs to see all successful and failed authentication attempts for a specific user across the environment. Which data source should be the primary source for this information?

    Select an answer first
  4. 19expert · hard

    A security operations team is investigating a series of failed login attempts followed by a successful login from an unusual location. They want to determine if the successful login was legitimate. Which data source would provide the most useful context?

    Select an answer first
  5. 20foundation · easy

    Which type of system is designed to maintain a centralized record of IT assets, their configurations, and relationships, often used to provide context for security incidents?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.