Objective 2.2

Cybersecurity Defense Architect

Identify data sources critical to cybersecurity operations, such as event sources, identity directories, asset management systems, and vulnerability - assessments. This can include non-security data sources, eg. observability tools

Objective 2.2 sits in Security Data Management, which carries 20% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-2Security Data Management

An engineer asks which devices supply the network domain data in Enterprise Security. Which set does Splunk name?

Directory servers and databasesDirectory data populates the identity domain instead.
Endpoint agents and mail relaysEndpoint agents feed the endpoint domain.
Firewalls, routers and scannersCorrect · your answerCorrect.
Backup servers and hypervisorsBackup and virtualisation systems are not the devices named here.

Correct.

Checked against help.splunk.com, August 2026

Concept

Listing the feeds by domain turns coverage into a checklist. A domain with one source is a gap even when the dashboards look populated.

Why C

Splunk documents network domain dashboards as displaying data provided by devices such as firewalls, routers, network intrusion detection systems, network vulnerability scanners, proxy servers and hosts.

Source

Network domain dashboards display network traffic data provided by devices such as firewalls, routers, network intrusion detection systems, network vulnerability scanners, proxy servers, and hosts.

Splunk Docs: Introduction to the dashboards available in Splunk Enterprise Security, checked August 2026
#data sources#coverage

Now you: objective 2.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

2-2Security Data Management

An engineer asks what identity directory data contributes once loaded into Enterprise Security. What does Splunk document?

Sample question 2 of 3

2-2Security Data Management

An engineer asks which endpoint data the Endpoint Protection domain is documented to carry. Which set does Splunk name?

Sample question 3 of 3

2-2Security Data Management

An architect asks which non-security data source Splunk documents as feeding the identity domain dashboards. Which is named?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Data Management