Exam objectives
Cybersecurity Defense ArchitectSplunk Certified Cybersecurity Defense Architect exam objectives
The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.
Titles and weightings from the official objectives. Splunk exam page ↗
Advanced Threat Intelligence and Analysis
5%of exam1.1 Develop and implement customized threat intelligence strategies, including both open source and commercial intelligence providersIn the bank
- 1.2 Integrate threat intelligence, including all aspects of the lifecycle (evaluation, curation, maintenance, sources, confidence scoring, etc.), into broader security operationsPractice
1.3 Integrate intelligence-informed advanced adversary emulation and threat modelingIn the bank
Security Data Management
20%of exam- 2.1 Explain how to develop and implement integration strategies for data-driven security operationsPractice
- 2.2 Identify data sources critical to cybersecurity operations, such as event sources, identity directories, asset management systems, and vulnerability - assessments. This can include non-security data sources, eg. observability toolsPractice
- 2.3 Identify high value / high signal / high noise data sources (e.g. Windows process vs EDR process flow, or network/VPC flow vs packet capture) and how they support security operations use casesPractice
- 2.4 Identify strategies to monitor an environment that requires nonstandard or out-of-band instrumentation and sensors, e.g. legacy data sources, OT/IC infrastructure environmentsPractice
- 2.5 Develop a data lifecycle management strategy, including retention, storage tiering, summarization, data residency, and access controlPractice
- 2.6 Describe the value of data normalization in order to support integration into cybersecurity defense programs, such as security monitoring and threat hunting, e.g. with CIM, CEFPractice
- 2.7 Implement security analytics strategies beyond traditional SIEM such as advanced techniques like data science, machine learning, behavioral analysis, and AIPractice
- 2.8 Explain how cybersecurity defense data architectures scale using technologies and capabilities such as data mesh, data lakes, message bus, message routing, and federated searchPractice
Advanced Incident Response and Management
10%of exam- 3.1 Align cybersecurity incident response with an organization’s incident management, change management, and other ITSM/ITIL processesPractice
- 3.2 Develop a process to manage, coordinate, and communicate responses to large-scale security incidentsPractice
- 3.3 Ensure appropriate technologies and processes are in place to support various forensics investigationsPractice
Advanced Automation and Orchestration
10%of exam- 4.1 Understand how an organization’s technical architectures, e.g. network design, enable or constrain security orchestrationPractice
- 4.2 Develop complex/cross platform automation to orchestrate workflows for cybersecurity operations such as investigation, detection, and incident responsePractice
- 4.3 Describe the benefits of an autonomous SOC, and strategies, processes, and technologies to develop onePractice
- 4.4 Leverage AI/ML for automated threat detection and responsePractice
Scaling Cybersecurity Defenses and DevSecOps
15%of exam- 5.1 Develop scalable strategies for agile and DevOps-driven cybersecurity defenses, such as detection as codePractice
- 5.2 Describe how to integrate security sensors and controls into DevOps workflows. -Practice
- 5.3 Describe how to create and leverage a SBOM (Software Bill of Materials) in cybersecurity defensesPractice
- 5.4 Describe continuous integration & deployment strategies for security data management and engineering solutionsPractice
5.5 Describe how to develop and implement patterns, architecture blueprints, and “paved roads” to enable cybersecurity defenses to scaleIn the bank
5.6 Understand how application and infrastructure architectures support cybersecurity defensesIn the bank
Governance, Risk, and Compliance
10%of exam- 6.1 Explain how governmental directives and regulations guidance publications like NIST CSF help influence the design of defense capabilitiesPractice
- 6.2 Explain how regulations like GDPR affect cyber defense architecture in relation to data privacy impact on logging, data sovereignty, and data residencyPractice
- 6.3 Explain how industry standard security frameworks (PCI, HIPAA, OT/IC, others) affect cyber defense architecturePractice
6.4 Define how security controls contribute to business operating cost and offsetting riskIn the bank
6.5 Explain how security technologies and controls fit into the organization’s Governance, Risk, and Compliance program and overall risk managementIn the bank
Measuring and Improving Security Program Effectiveness
15%of exam- 7.1 Explain how to define, measure, and report on metrics to assess and monitor a security program’s effectivenessPractice
- 7.2 Explain how a business’s risk tolerance informs a security program’s metricsPractice
- 7.3 Explain how Continuous Process Improvement can enrich and expand a metrics driven security program’s efficacyPractice
- 7.4 Explain how security controls are continually tested and gaps are remediatedPractice
Security Capability Selection, Placement, Configuration
15%of exam- 8.1 Identify organizational coverage for prevention, detection, response and recovery capabilitiesPractice
- 8.2 Determine how coverage gaps can be mitigated by architecture changes, config changes, or process changesPractice
- 8.3 Affect organizational and company priorities and budgets based on key capabilities required for security that are aligned to security and business goalsPractice
- 8.4 Explain methodologies used to select security technologies aligned to business need, organizational technology landscape, and security controlsPractice
- 8.5 Define technology implementation strategies to provide desired capabilitiesPractice
- 8.6 Ensure that resilient solutions aligned to the business and operational requirements are selected and deployed. -Practice
Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to Splunk documentation.
Keep reading
Cybersecurity Defense Architect practice questions
Free sample questions with the full explanation on every answer.
Free Cybersecurity Defense Architect practice test
Ten real questions, playable now. No account, no card.
Cybersecurity Defense Architect passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is Cybersecurity Defense Architect?
An honest difficulty read from the format, the clock and the weights.