Objective 2.3

Cybersecurity Defense Analyst

Identify the common tiers of Threat Intelligence and how they might be applied to threat analysis

Objective 2.3 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-3Threat and Attack Types, Motivations, and Tactics

An analyst asks how the threat intelligence types supported by Enterprise Security relate to how it is stored. What does Splunk document?

They correspond to data modelsData models describe event data rather than intelligence storage.
They map to separate indexesThreat matches are written to an index, but the types are collections.
They match KV Store collectionsCorrect · your answerCorrect.
They map to correlation searchesCorrelation searches consume the intelligence instead of holding it.

Correct.

Checked against help.splunk.com, August 2026

Concept

Intelligence is stored by the kind of observable it holds, because that is what a search has to match against. A file hash and a URL cannot share one lookup usefully.

Why C

Splunk documents that the supported types of threat intelligence correspond to the KV Store collections in which the intelligence is stored.

Source

Splunk Enterprise Security supports several types of threat intelligence. The supported types of threat intelligence correspond to the KV Store collections in which the threat intelligence is stored.

Splunk Docs: Supported types of threat intelligence in Splunk Enterprise Security, checked August 2026
#threat intelligence#collections

Now you: objective 2.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-3Threat and Attack Types, Motivations, and Tactics

An administrator asks what the weight assigned to a piece of intelligence changes. What does Splunk document?

Sample question 2 of 3

2-3Threat and Attack Types, Motivations, and Tactics

An analyst asks which intelligence collection would hold a malicious file hash in Enterprise Security. Which does Splunk name?

Sample question 3 of 3

2-3Threat and Attack Types, Motivations, and Tactics

An administrator wants to load structured threat intelligence from an external partner into Enterprise Security. Which formats does Splunk document uploading?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Threat and Attack Types, Motivations, and Tactics