
SplunkCertified Cybersecurity Defense Architect
Domain 8Objective 5
Define Technology Implementation Strategies to Provide Desired Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)
Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
1concept
15%of the exam
Questions 1–5
- 1
A security architect is deploying Splunk ES for a company that has a mix of sensitive data (PII) and non-sensitive operational logs. The company must restrict access to PII to a small team of analysts. The architect needs to ensure that the PII is not searchable by the general SOC team. Which strategy is most appropriate?
Select an answer first - 2
A Splunk Cybersecurity Defense Architect is defining a technology implementation strategy for a new security operations center. The primary goal is to ensure that the chosen technologies directly support the required security capabilities. Which approach best aligns with this goal?
Select an answer first - 3
An organization is deploying Splunk ES and needs to ingest Windows security logs from 5,000 endpoints. The security team is concerned about the load on the domain controllers and wants to minimize the impact on production systems. Which ingestion strategy should the architect choose?
Select an answer first - 4
A company is deploying Splunk ES and wants to detect brute-force attacks on their VPN. The VPN logs are currently sent to a syslog server. The architect needs to ingest these logs into Splunk and create a correlation search. What is the first step in the implementation strategy?
Select an answer first - 5
A company is deploying Splunk ES and wants to monitor user activity on their custom web application. The application logs access events to a file on each web server. The security team wants to correlate this with Active Directory (AD) login events. Which ingestion strategy should the architect use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.