Objective 2.3

Cybersecurity Defense Architect

Identify high value / high signal / high noise data sources (e.g. Windows process vs EDR process flow, or network/VPC flow vs packet capture) and how they support security operations use cases

Objective 2.3 sits in Security Data Management, which carries 20% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-3Security Data Management

An engineer weighs packet capture against log collection. What advantage does Splunk document for packet data?

Automatic normalisationNormalisation still requires an add-on and the CIM.
A lower storage costPacket capture is heavier to store rather than cheaper.
Simpler retention rulesRetention of high volume capture is harder to plan, not simpler.
Detail logs do not collectCorrect · your answerCorrect.

Correct.

Checked against help.splunk.com, August 2026

Concept

Packet data is expensive and answers questions logs cannot. That trade is the whole argument for capturing it in some places and not others.

Why D

Splunk documents that packet capture data contains security-relevant information not typically collected in log files.

Source

Packet capture data contains security-relevant information not typically collected in log files. Integrating network protocol data provides a rich source of additional context when detecting, monitoring, and responding to security related threats.

Splunk Docs: Protocol Intelligence dashboards, checked August 2026
#data sources#signal

Now you: objective 2.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

2-3Security Data Management

An engineer must choose between the Network Traffic and Intrusion Detection models for a firewall feed. Which basis does Splunk document for Network Traffic?

Sample question 2 of 2

2-3Security Data Management

An engineer asks how Intrusion Detection differs in when traffic is denied. What does Splunk document?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Data Management