
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 1
Align Cybersecurity Incident Response with an Organizations Incident Management, Change Management, and Other ITSM/ITIL Processes. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
10%of the exam
Questions 16–20
- 16
A security incident required a temporary firewall rule change to block malicious traffic. After the incident, the change was not documented, and the rule remained in place. What should the organization do to align with change management and prevent this in the future?
Select an answer first - 17
A security analyst detects a suspected ransomware infection on a single workstation. The organization's IT service desk uses an ITSM tool for all incident tickets. The security team has its own incident response playbook. According to the principle of aligning cybersecurity incident response with broader IT incident management, what should the analyst do first?
Select an answer first - 18
Why is it important to document cybersecurity incident response actions as changes in the change management system?
Select an answer first - 19
A security operations center (SOC) is reviewing its incident response procedures. They notice that cybersecurity incidents are often handled by the IT service desk first, causing delays in escalation to the security team. What is the best way to align cybersecurity incident response with IT incident management to reduce these delays?
Select an answer first - 20
A security incident requires a critical firewall rule change to contain the threat. The change management policy requires all changes to be approved by the change advisory board (CAB). However, the next CAB meeting is in two days. What is the most appropriate action to align with change management while ensuring timely containment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.