
SplunkCertified Cybersecurity Defense Architect
Domain 2Objective 7
Implement Security Analytics Strategies Beyond Traditional SIEM Such as Advanced Techniques Like Data Science, Machine Learning, Behavioral Analysis, and AI. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)
Part of the Security Data Management domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
A Splunk architect is designing a system to detect data exfiltration via DNS tunneling. The security team has observed that DNS tunneling often involves queries with high entropy subdomains and a high volume of requests. The architect has access to DNS logs and wants to use statistical modeling to detect this behavior. However, the environment also has legitimate dynamic DNS services that generate high-entropy subdomains. Which approach best distinguishes malicious tunneling from legitimate dynamic DNS?
Select an answer first - 7
How can machine learning models be integrated into a SIEM platform to enhance security analytics?
Select an answer first - 8
Which machine learning algorithm type is best suited for grouping similar security events into clusters to identify previously unknown attack patterns?
Select an answer first - 9
What is a common approach to incorporate behavioral analysis into a SIEM platform?
Select an answer first - 10
A Splunk architect is asked to improve the detection of a new malware variant that communicates with command-and-control (C2) servers using short, periodic beaconing intervals. The existing correlation rules only look for a fixed number of connections to a known bad IP address. The architect wants to use statistical modeling to detect the beaconing pattern without relying on a static list of C2 IPs. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.