Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 3

Identify High Value / High Signal / High Noise Data Sources (e.g. Windows Process vs EDR Process Flow, or network/VPC Flow vs Packet Capture) and How They Support Security Operations Use Cases. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A SOC team is evaluating a new data source that generates a large volume of events, but only a small fraction are related to security incidents. The team wants to use this source for detection without overwhelming their analysts. What is the most effective approach?

    Select an answer first
  2. 17application · medium

    A SOC team is overwhelmed by alerts from their SIEM. They notice that a large number of alerts are triggered by routine administrative activities, such as scheduled tasks and legitimate software updates. The team wants to reduce alert fatigue while maintaining visibility into genuine threats. Which approach would best address this issue?

    Select an answer first
  3. 18application · medium

    A security analyst needs to detect data exfiltration attempts that involve large file transfers over the network. The organization has limited storage for log data and needs a solution that provides high signal with manageable noise. Which data source would best meet this requirement?

    Select an answer first
  4. 19application · medium

    A security architect is designing a monitoring strategy for a financial institution. The institution is most concerned about insider threats and credential misuse. Which data source would be considered high value for this specific concern?

    Select an answer first
  5. 20expert · hard

    A SOC team is evaluating a new data source that provides detailed endpoint activity but generates a high volume of events. The team wants to use this source for threat hunting but is concerned about the storage and processing costs. They need to balance the value of the data with the operational overhead. What is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.