Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 1Objective 2

Integrate Threat Intelligence, Including All Aspects of the Lifecycle (evaluation, Curation, Maintenance, Sources, Confidence Scoring, Etc.), into Broader Security Operations. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Advanced Threat Intelligence and Analysis domain, which accounts for 5% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
5%of the exam

Questions 16–20

  1. 16foundation · easy

    Which phase of the threat intelligence lifecycle involves transforming raw collected data into a structured format that can be analyzed for indicators of compromise?

    Select an answer first
  2. 17application · medium

    A company wants to share threat intelligence with a trusted partner organization. They need a standardized format and a transport mechanism that supports automated sharing. Which combination should they use?

    Select an answer first
  3. 18application · medium

    A threat intelligence repository contains indicators that were added over the past year. Some indicators are no longer considered malicious by the community, and others have not been seen in any detection for months. The team wants to keep the repository accurate and reduce false positives. What should they do?

    Select an answer first
  4. 19foundation · easy

    Which criterion for evaluating a threat intelligence feed assesses whether the information is current enough to be useful for detecting active threats?

    Select an answer first
  5. 20application · medium

    A security team wants to operationalize threat intelligence by mapping indicators to MITRE ATT&CK techniques. They have a large number of indicators and want to prioritize alerts based on the techniques they represent. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.