Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 8Objective 5

Define Technology Implementation Strategies to Provide Desired Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)

Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)

16questions here
4free pages
1concept
15%of the exam

Questions 6–10

  1. 6application · medium

    A company is deploying Splunk ES and wants to detect insider threats by correlating employee badge access, VPN logs, and HR data. The HR data is stored in a SQL database and is updated daily. Which approach should the architect take to make HR data available for correlation?

    Select an answer first
  2. 7application · hard

    A multinational company wants to deploy Splunk ES across three regions (US, EU, Asia) to support a global SOC. The SOC operates 24/7 and needs a single pane of glass for investigations. Data residency regulations require that EU citizen data stays in the EU. Which architecture should the architect recommend?

    Select an answer first
  3. 8application · medium

    A security architect is deploying Splunk ES for a company that uses a mix of Windows and Linux servers. The team wants to centralize log collection and reduce the number of agents installed on servers. Which strategy should the architect recommend?

    Select an answer first
  4. 9application · hard

    A security architect is designing a Splunk ES deployment for a company that experiences occasional spikes in log volume (e.g., during a DDoS attack). The company wants to avoid paying for idle capacity during normal operations. Which deployment strategy best addresses this need?

    Select an answer first
  5. 10application · medium

    A financial services firm is deploying Splunk Enterprise Security (ES) and needs to ingest data from a legacy mainframe that only supports syslog over UDP. The security team requires guaranteed delivery of all security events to meet audit requirements. The mainframe team cannot install any additional software on the host. What implementation strategy should the architect recommend?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.