Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Engineer

Domain 3Objective 1

Research, Incorporate and Develop Threat Intelligence. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 3)

Part of the Building Effective Security Processes and Programs domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A company uses Splunk ES and wants to integrate a new threat intelligence feed. The feed provides indicators in STIX/TAXII format, but the team is unfamiliar with this format. They need to automate the ingestion and ensure the indicators are used in detection. What is the best approach?

    Select an answer first
  2. 12foundation · easy

    A threat intelligence analyst is evaluating a report about a new zero-day vulnerability. The report was published six months ago, and the vendor has already released a patch. Which evaluation criterion is most important to consider when deciding whether to act on this intelligence?

    Select an answer first
  3. 13application · medium

    A threat intelligence analyst is reviewing a new feed that provides indicators for a specific malware family. The feed has a high volume of indicators, but many are duplicates or have been seen in other feeds. The analyst wants to ensure the intelligence is useful. What is the most important factor to evaluate?

    Select an answer first
  4. 14foundation · easy

    A threat intelligence team wants to share information about a new phishing campaign with other organizations in the same sector. Which collection method is most appropriate for this collaborative sharing?

    Select an answer first
  5. 15expert · hard

    A security team wants to collect threat intelligence on a new ransomware group that is targeting their region. They have a small budget and need to act quickly. They are considering joining a local ISAC, subscribing to a commercial feed, and conducting manual research. Which approach is most effective given the constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.