Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 5Objective 3

Describe How to Create and Leverage a SBOM (Software Bill of Materials) in Cybersecurity Defenses. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)

Part of the Scaling Cybersecurity Defenses and DevSecOps domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
8concepts
15%of the exam

Questions 6–10

  1. 6application · medium

    A company releases a mobile application that includes a third-party SDK. Six months later, a critical vulnerability is disclosed in that SDK. The security team wants to determine if the released application is affected. The SBOM was generated at build time and has not been updated since. What is the most significant limitation of using this SBOM?

    Select an answer first
  2. 7expert · hard

    A DevOps team wants to enforce a policy that blocks a build if any component in the SBOM has a critical vulnerability. The team uses a CI pipeline and generates a CycloneDX SBOM for each build. However, some builds are failing because the vulnerability scanner is flagging vulnerabilities in test dependencies that are not included in the final artifact. What is the most effective way to address this issue?

    Select an answer first
  3. 8foundation · easy

    What is a key advantage of automated SBOM generation over manual compilation?

    Select an answer first
  4. 9expert · hard

    An organization is required to provide SBOMs to a regulatory body. The SBOMs must be accurate and up-to-date at the time of submission. The organization has a mix of legacy applications that are no longer built and modern applications that are built continuously. What is the most appropriate strategy for the legacy applications?

    Select an answer first
  5. 10application · medium

    A security architect is explaining the value of SBOMs to executive leadership. The executives want to understand how SBOMs improve the organization's security posture beyond just listing components. Which benefit should the architect highlight as the primary security advantage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.