Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 8Objective 5

Define Technology Implementation Strategies to Provide Desired Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)

16questions here
4free pages
1concept
15%of the exam

Questions 11–15

  1. 11application · medium

    A company is deploying Splunk ES and wants to monitor cloud infrastructure (AWS, Azure, GCP) alongside on-premises systems. The security team wants a unified view of all security events. Which implementation strategy should the architect recommend?

    Select an answer first
  2. 12expert · hard

    A large enterprise is deploying Splunk ES and has a requirement to retain all security logs for 5 years for legal reasons. However, the security team only needs to search the last 6 months for active investigations. The data volume is massive, and the budget is limited. The architect must balance retention, searchability, and cost. Which strategy is the most cost-effective while meeting all requirements?

    Select an answer first
  3. 13application · medium

    A security architect is implementing Splunk ES for a large enterprise. The SOC team wants to create custom correlation searches, but they are not familiar with SPL. The architect needs to enable the team to build detections quickly without writing code. Which feature should the architect enable?

    Select an answer first
  4. 14application · medium

    A company is deploying Splunk ES and wants to ingest data from a variety of sources, including custom applications that output JSON. The architect needs to ensure that the data is parsed correctly and available for correlation searches. What is the most efficient way to handle this?

    Select an answer first
  5. 15expert · hard

    A global bank is deploying Splunk ES and must comply with GDPR for EU customer data. The bank's SOC is centralized in the US. The architect must ensure that EU data is not transferred outside the EU while still allowing US analysts to investigate incidents. Which strategy satisfies both requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.