
SplunkCertified Cybersecurity Defense Architect
Domain 2Objective 2
Identify Data Sources Critical to Cybersecurity Operations, Such as Event Sources, Identity Directories, Asset Management Systems, and Vulnerability - Assessments. This Can Include Non-Security Data Sources, Eg. Observability Tools. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 5)
Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
20%of the exam
Questions 21–25
- 21
During an investigation of a suspicious login, an analyst needs to determine if the user account is active, when the password was last changed, and which groups the user belongs to. Which data source should the analyst query?
Select an answer first - 22
Which data source is most directly relevant for determining whether a specific system has known vulnerabilities that could be exploited?
Select an answer first - 23
Why is it important to include identity directory logs in a security data strategy?
Select an answer first - 24
Which cybersecurity event source is specifically designed to detect and alert on suspicious activity occurring on individual hosts, such as unusual process execution or file modifications?
Select an answer first - 25
What type of information from an asset management system helps security analysts determine which devices are most critical to the business and should be prioritized during an incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.