
SplunkCertified Cybersecurity Defense Architect
Domain 1Objective 2
Integrate Threat Intelligence, Including All Aspects of the Lifecycle (evaluation, Curation, Maintenance, Sources, Confidence Scoring, Etc.), into Broader Security Operations. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)
Part of the Advanced Threat Intelligence and Analysis domain, which accounts for 5% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
9concepts
5%of the exam
Questions 6–10
- 6
A security team is considering using a community threat intelligence feed. The feed is free and provides a large number of indicators, but the team is concerned about the reliability of the indicators. They want to use the feed but mitigate the risk of false positives. What should they do?
Select an answer first - 7
A security team uses a threat intelligence platform that assigns confidence scores to indicators. They notice that indicators from a particular commercial feed consistently receive high scores, but several of these indicators have resulted in false positives. The team suspects the feed's scoring is inflated. What should they do to improve the accuracy of confidence scores?
Select an answer first - 8
Which curation process involves adding contextual information, such as threat actor attribution or MITRE ATT&CK techniques, to raw indicators to make them more actionable?
Select an answer first - 9
A threat intelligence repository contains an indicator that was associated with a specific malware campaign. The campaign has been inactive for six months, and the indicator has not been observed in any recent detections. The team wants to maintain the repository's accuracy. What should they do with this indicator?
Select an answer first - 10
A security team maintains a threat intelligence repository that is used to block malicious domains. They notice that some domains are being blocked but are no longer malicious, causing legitimate users to be affected. The team wants to reduce these false positives while maintaining security. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.