Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 3

Identify High Value / High Signal / High Noise Data Sources (e.g. Windows Process vs EDR Process Flow, or network/VPC Flow vs Packet Capture) and How They Support Security Operations Use Cases. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    A network security team is investigating a potential command-and-control (C2) communication. They need to determine if the traffic is malicious by examining the content of the packets, including payload data. Which data source would provide the necessary detail for this investigation?

    Select an answer first
  2. 12expert · hard

    A security architect is designing a monitoring solution for a hybrid cloud environment. The team needs to detect both external attacks and internal lateral movement. They have a limited budget and cannot afford full packet capture for all traffic. Which data source combination would provide the best coverage within budget?

    Select an answer first
  3. 13application · medium

    A security operations center (SOC) is investigating a suspected privilege escalation attack. The team needs to understand the full sequence of process creation, including parent-child relationships, command-line arguments, and any file or registry modifications made by the malicious process. Currently, they have Windows Security Event logs (Event ID 4688) that capture process creation with command lines. Which additional data source would provide the most value for this investigation?

    Select an answer first
  4. 14application · medium

    A cloud security team needs to monitor traffic within their VPC for potential lateral movement. They want to detect unusual communication patterns between instances without incurring the high storage cost of full packet capture. Which data source would best meet this requirement?

    Select an answer first
  5. 15foundation · easy

    How does a high signal data source support security operations?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.