
SplunkCertified Cybersecurity Defense Architect
Domain 4Objective 4
Leverage AI/ML for Automated Threat Detection and Response. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)
Part of the Advanced Automation and Orchestration domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
10%of the exam
Questions 1–5
- 1
A data science team trains a model to detect malicious PowerShell commands. They split their data into 80% training and 20% test sets. The model performs well on the test set but poorly on live data. Which validation mistake is most likely?
Select an answer first - 2
What is the primary purpose of an automated threat response workflow triggered by an AI/ML detection output?
Select an answer first - 3
A Splunk SOAR playbook is triggered by an AI/ML model alert. The playbook's first action is to query an external threat-intelligence service. The query times out, causing the playbook to fail. What is the best way to make the playbook more resilient?
Select an answer first - 4
What is a common strategy to reduce false positives in an AI/ML-based threat detection system?
Select an answer first - 5
A model that detects malicious URLs is trained on a dataset collected last year. The model's performance has declined because attackers now use shorter-lived domains. The architect needs to update the model. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.