Objective 1.2

Cybersecurity Defense Architect

Integrate threat intelligence, including all aspects of the lifecycle (evaluation, curation, maintenance, sources, confidence scoring, etc.), into broader security operations

Objective 1.2 sits in Advanced Threat Intelligence and Analysis, which carries 5% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-2Advanced Threat Intelligence and Analysis

An analyst designs a maintenance check for intelligence feeds. Which documented signal confirms a URL-based source is arriving?

The threat_activity index countMatch volume can fall for reasons other than a failed download.
The download_status columnCorrect · your answerCorrect.
The notable event countNotable counts reflect detection rather than feed health.
The risk index volumeRisk index volume measures scoring activity.

Correct.

Checked against help.splunk.com, August 2026

Concept

A feed that silently stops leaves detections quietly blind. Checking arrival separately from matching is what makes that failure visible.

Why B

Splunk documents finding the source on the Threat Intelligence Audit dashboard and confirming that the download_status column states threat list downloaded.

Source

Find the intelligence source and confirm that the download_status column states threat list downloaded .

Splunk Docs: Verify that you have added intelligence successfully, checked August 2026
#threat intelligence#lifecycle

Now you: objective 1.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

1-2Advanced Threat Intelligence and Analysis

An analyst asks how often parsed intelligence reaches the KV Store collections. What does Splunk document?

Sample question 2 of 2

1-2Advanced Threat Intelligence and Analysis

An analyst asks what the supported intelligence types correspond to in storage terms. What does Splunk document?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.