
SplunkCertified Cybersecurity Defense Engineer
Domain 3Objective 1
Research, Incorporate and Develop Threat Intelligence. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 2)
Part of the Building Effective Security Processes and Programs domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
20%of the exam
Questions 6–10
- 6
A threat intelligence analyst is evaluating a new feed that claims to provide early warning of zero-day exploits. The feed has a high reputation but has not been used by the organization before. The analyst needs to decide whether to integrate this feed into their SIEM. What is the most important consideration?
Select an answer first - 7
A security analyst is evaluating two threat intelligence feeds. Feed A provides a high volume of indicators with frequent updates but has a high false-positive rate. Feed B provides fewer indicators but is highly accurate and specific to the organization's industry. The analyst needs to reduce alert fatigue while maintaining detection coverage. Which feed should the analyst prioritize?
Select an answer first - 8
A security analyst receives a threat intelligence report from an open-source feed indicating a new malware family is targeting the company's industry. The report includes indicators of compromise (IOCs) but lacks context on the malware's behavior. The analyst has limited time and must decide whether to act. What should the analyst do first?
Select an answer first - 9
A security team is building a threat intelligence program from scratch. They have a limited budget and need to cover a wide range of threats. They are considering using open-source feeds, commercial feeds, and government alerts. Which strategy is most effective for building a sustainable program?
Select an answer first - 10
A security operations team uses a SOAR platform to automate incident response. They want to incorporate threat intelligence from a commercial feed to automatically enrich alerts and trigger response actions. What is the best way to integrate this intelligence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.