Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 2Objective 7

Implement Security Analytics Strategies Beyond Traditional SIEM Such as Advanced Techniques Like Data Science, Machine Learning, Behavioral Analysis, and AI. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)

Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
20%of the exam

Questions 1–5

  1. 1expert · hard

    A global bank uses Splunk ES to monitor transactions. The fraud team wants to use AI to detect money laundering patterns. They have labeled data of confirmed money laundering cases and non-fraudulent transactions. The bank's compliance officer requires that every alert generated by the AI model be explainable to auditors. Which approach best satisfies the need for both accurate detection and explainability?

    Select an answer first
  2. 2foundation · easy

    What is a key role of artificial intelligence (AI) in security operations?

    Select an answer first
  3. 3expert · hard

    A Splunk architect is implementing UEBA (User and Entity Behavior Analytics) for a manufacturing company. The company has a mix of human users and IoT devices (e.g., sensors, cameras) that connect to the network. The architect wants to detect compromised IoT devices, which often exhibit unusual communication patterns. Which approach is most effective for establishing baselines for both humans and IoT devices?

    Select an answer first
  4. 4application · medium

    A Splunk architect is working with a retail company that experiences seasonal spikes in login attempts. They want to use predictive analytics to forecast the expected volume of authentication events so that they can distinguish a genuine surge from an attack. Which data science technique is most appropriate?

    Select an answer first
  5. 5application · medium

    A university's Splunk deployment monitors student and faculty access to a research database. The security team wants to detect compromised accounts by identifying when a user accesses data at unusual times or from unusual locations. They have six months of historical authentication and access logs. Which behavioral analysis approach should they use to establish a baseline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.