
SplunkCertified Cybersecurity Defense Engineer
Domain 3Objective 1
Research, Incorporate and Develop Threat Intelligence. CYBERSECURITY-DEFENSE-ENGINEER Practice Questions (Page 4)
Part of the Building Effective Security Processes and Programs domain, which accounts for 20% of the CYBERSECURITY-DEFENSE-ENGINEER exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~6–10 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
20%of the exam
Questions 16–20
- 16
A security analyst discovers a new command-and-control (C2) domain used by a threat actor targeting the company. The analyst needs to inform the network team and the incident response team. What is the most effective way to disseminate this intelligence?
Select an answer first - 17
A threat intelligence analyst is tasked with developing custom threat intelligence for the organization. Which internal data source would be most valuable for this purpose?
Select an answer first - 18
A security operations center has integrated a new threat intelligence feed into their SIEM. The feed generates a high number of alerts, many of which are false positives. The SOC manager wants to reduce alert fatigue while still leveraging the intelligence. What is the best approach?
Select an answer first - 19
A security analyst is categorizing threat intelligence sources for a new threat intelligence program. Which of the following is an example of an external open-source threat intelligence feed?
Select an answer first - 20
A threat intelligence analyst receives a report about a malware campaign that targets a specific type of industrial control system (ICS) software. The organization does not use that software. Which aspect of the intelligence should the analyst primarily consider when evaluating its applicability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ENGINEER” is a trademark of its owner, used for identification only.