Objective 2.3
Cybersecurity Defense AnalystIdentify the common tiers of Threat Intelligence and how they might be applied to threat analysis
Objective 2.3 sits in Threat and Attack Types, Motivations, and Tactics, which carries 20% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An analyst asks how the threat intelligence types supported by Enterprise Security relate to how it is stored. What does Splunk document?
Correct.
Checked against help.splunk.com, August 2026Concept
Intelligence is stored by the kind of observable it holds, because that is what a search has to match against. A file hash and a URL cannot share one lookup usefully.
Why C
Splunk documents that the supported types of threat intelligence correspond to the KV Store collections in which the intelligence is stored.
Source
Splunk Docs: Supported types of threat intelligence in Splunk Enterprise Security, checked August 2026Splunk Enterprise Security supports several types of threat intelligence. The supported types of threat intelligence correspond to the KV Store collections in which the threat intelligence is stored.
Now you: objective 2.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An administrator asks what the weight assigned to a piece of intelligence changes. What does Splunk document?
Sample question 2 of 3
An analyst asks which intelligence collection would hold a malicious file hash in Enterprise Security. Which does Splunk name?
Sample question 3 of 3
An administrator wants to load structured threat intelligence from an external partner into Enterprise Security. Which formats does Splunk document uploading?
Full Cybersecurity Defense Analyst question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Threat and Attack Types, Motivations, and Tactics
- 2.1 Recognize common types of attacks and attack vectors
- 2.2 Define common terms including supply chain attack, ransomware, registry, exfiltration, social engineering, DoS, DDoS, bot and botnet, C2, zero trust, account takeover, email compromise, threat actor, APT, adversary
- 2.4 Outline the purpose and scope of annotations within Splunk Enterprise Security
- 2.5 Define tactics, techniques and procedures and how they are regarded in the industry