Objective 2.2
Cybersecurity Defense ArchitectIdentify data sources critical to cybersecurity operations, such as event sources, identity directories, asset management systems, and vulnerability - assessments. This can include non-security data sources, eg. observability tools
Objective 2.2 sits in Security Data Management, which carries 20% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An engineer asks which devices supply the network domain data in Enterprise Security. Which set does Splunk name?
Correct.
Checked against help.splunk.com, August 2026Concept
Listing the feeds by domain turns coverage into a checklist. A domain with one source is a gap even when the dashboards look populated.
Why C
Splunk documents network domain dashboards as displaying data provided by devices such as firewalls, routers, network intrusion detection systems, network vulnerability scanners, proxy servers and hosts.
Source
Splunk Docs: Introduction to the dashboards available in Splunk Enterprise Security, checked August 2026Network domain dashboards display network traffic data provided by devices such as firewalls, routers, network intrusion detection systems, network vulnerability scanners, proxy servers, and hosts.
Now you: objective 2.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An engineer asks what identity directory data contributes once loaded into Enterprise Security. What does Splunk document?
Sample question 2 of 3
An engineer asks which endpoint data the Endpoint Protection domain is documented to carry. Which set does Splunk name?
Sample question 3 of 3
An architect asks which non-security data source Splunk documents as feeding the identity domain dashboards. Which is named?
Full Cybersecurity Defense Architect question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Data Management
- 2.1 Explain how to develop and implement integration strategies for data-driven security operations
- 2.3 Identify high value / high signal / high noise data sources (e.g. Windows process vs EDR process flow, or network/VPC flow vs packet capture) and how they support security operations use cases
- 2.4 Identify strategies to monitor an environment that requires nonstandard or out-of-band instrumentation and sensors, e.g. legacy data sources, OT/IC infrastructure environments
- 2.5 Develop a data lifecycle management strategy, including retention, storage tiering, summarization, data residency, and access control
- 2.6 Describe the value of data normalization in order to support integration into cybersecurity defense programs, such as security monitoring and threat hunting, e.g. with CIM, CEF
- 2.7 Implement security analytics strategies beyond traditional SIEM such as advanced techniques like data science, machine learning, behavioral analysis, and AI
- 2.8 Explain how cybersecurity defense data architectures scale using technologies and capabilities such as data mesh, data lakes, message bus, message routing, and federated search