
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 1
Align Cybersecurity Incident Response with an Organizations Incident Management, Change Management, and Other ITSM/ITIL Processes. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 5)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
10%of the exam
Questions 21–25
- 21
A security analyst is handling a phishing incident that has affected multiple users. The organization's ITSM tool has a predefined incident workflow. What should the analyst do to ensure the incident is properly tracked and escalated?
Select an answer first - 22
In ITIL, which process is primarily responsible for identifying the underlying cause of recurring cybersecurity incidents?
Select an answer first - 23
Which statement best distinguishes cybersecurity incident response from broader IT incident management?
Select an answer first - 24
After a significant security incident, the incident response team conducts a post-incident review. They identify several areas for improvement in the response process. According to ITIL/ITSM continuous improvement practices, what should the team do with these findings?
Select an answer first - 25
In an ITSM incident workflow, what typically triggers an escalation of a cybersecurity incident ticket?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.