Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 6Objective 4

Define How Security Controls Contribute to Business Operating Cost and Offsetting Risk. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Governance, Risk, and Compliance domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
5concepts
10%of the exam

Questions 16–20

  1. 16foundation · easy

    When budgeting for a new security information and event management (SIEM) platform, which of the following is considered a direct cost?

    Select an answer first
  2. 17application · medium

    A company is considering a security control that costs $75,000/year. The control is expected to reduce the probability of a $500,000 breach from 15% to 5%. The company's risk appetite is moderate, and they are willing to accept some residual risk. What is the NET financial benefit of this control?

    Select an answer first
  3. 18expert · hard

    A company has a low risk appetite and is evaluating two security controls for a critical application. Control A costs $150,000/year and reduces the probability of a $1,000,000 breach from 10% to 2%. Control B costs $80,000/year and reduces the probability of the same breach from 10% to 5%. The company has a budget of $200,000 for security controls. Which option BEST aligns with the company's low risk appetite and budget?

    Select an answer first
  4. 19application · medium

    A company is considering a security control that costs $100,000/year. The control is expected to reduce the probability of a $1,000,000 breach from 20% to 5%. The company's risk appetite is moderate, and they are willing to accept some residual risk. What is the ANNUALIZED LOSS EXPECTANCY (ALE) after implementing the control?

    Select an answer first
  5. 20application · medium

    A manufacturing company is considering two risk mitigation options for a legacy system that cannot be patched. Option A: implement a network segmentation control that isolates the system, costing $30,000/year. Option B: purchase a cyber insurance policy that covers losses from a breach of the system, costing $25,000/year. The company's risk appetite is low, and the system is critical to production. Which approach BEST aligns with the company's risk appetite?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.