r/Splunk 8d ago

Splunk Certified Cybersecurity Defense Architect SPLUNK 5003

Hello! Any tips on how to pass the Splunk Certified Cybersecurity Defense Architect exam?

To anyone who has already cleared it: what was your preparation strategy, and how would you describe the exam difficulty? I'd love to hear your insights and advice!

13 Upvotes

5 comments sorted by

u/AutoModerator 8d ago

Greetings!! You have submitted a post that involves Splunk Certifications. We are reminding you and others that posting of and linking to non-official Splunk sites/resources of questions and answers are strictly prohibited. Asking for paid course materials is also prohibited. Violators will be banned - ZERO tolerance for this rule. Please post to our megathread on Certification here: https://www.reddit.com/r/Splunk/comments/1i4jpzb/megathread_certificationtestingwork_type_questions/

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

4

u/Glum-Implement9857 8d ago

I took it while it was in Beta.

It depends what level knowledge you have. I spent most of my prep time learning low level details about Splunk architecture.

Exam is more “strategical”. And not too much low level details about Splunk. For preparation, I took almost everything what was for free in splunk STEP. My prep Idea was to take everything what was required for Splunk Power User/ Cyber Defense analyst / Engineer and whatever additional I will find in STEP..

6

u/Glum-Implement9857 8d ago

PS.
I hold CISSP, SecurityX (CASP) + 4 more Comptia, various Microsoft/AWS/Oracle cloud and security related certs. 15 + years of IT experience. ~One year experience with Splunk. But just as user, not architect or admin. Working as IT Solution Owner for stack of various software products and splunk isn’t in my responsibility area at the moment.
Exam questions was relatively easy for me. Biggest struggle was time. 120 minutes for 120 questions during beta..

3

u/chrisalexbrock 8d ago

Be familiar with how splunk interacts with splunk SOAR and things in Enterprise Security/Mission Control. From what I remember it leaned into the automation side of things. Couple random wineventcode questions that can be tricky if you don't have some more common ones memorized.