Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 3Objective 1

Align Cybersecurity Incident Response with an Organizations Incident Management, Change Management, and Other ITSM/ITIL Processes. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)

Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts
10%of the exam

Questions 1–5

  1. 1expert · hard

    A security operations center (SOC) is integrating its incident response workflow with the organization's ITSM tool. They want to ensure that security incidents are automatically escalated to the appropriate teams based on severity. What is the best way to achieve this?

    Select an answer first
  2. 2expert · hard

    An organization has a high rate of recurring security incidents caused by misconfigured cloud resources. The security team wants to reduce these incidents. Which combination of ITIL processes should they integrate with to address both the immediate incidents and the underlying configuration issues?

    Select an answer first
  3. 3expert · hard

    An organization is developing a communication plan for cybersecurity incidents. They want to ensure that during a major incident, the CEO, legal counsel, and the IT service desk are informed promptly, but not overwhelmed with unnecessary details. What is the best approach?

    Select an answer first
  4. 4expert · hard

    An organization is integrating its security incident response with ITIL processes. They want to ensure that security incidents are properly documented and that any changes made during the response are tracked. Which combination of ITIL processes should they integrate with?

    Select an answer first
  5. 5application · medium

    During a security incident, the response team needs to block a malicious IP address at the firewall. The organization's change management policy requires all firewall changes to be approved by the change advisory board (CAB). However, the incident is time-sensitive and waiting for the next CAB meeting would delay containment. What is the best approach to align with change management while addressing the urgency?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.