Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 5Objective 3

Describe How to Create and Leverage a SBOM (Software Bill of Materials) in Cybersecurity Defenses. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Scaling Cybersecurity Defenses and DevSecOps domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
8concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A security team needs to choose an SBOM format for a new project. The project requires detailed dependency relationships and the ability to include vulnerability data directly in the SBOM. The team also wants to use a format that is widely supported by commercial tools. Which format should they select?

    Select an answer first
  2. 12expert · hard

    A security team has SBOMs for all applications in production. A new critical vulnerability is disclosed in a widely used logging library. The team must determine which applications are affected and prioritize remediation. The SBOMs are in SPDX format and were generated at the last release. Some applications have not been released for over a year. What is the most significant challenge the team faces?

    Select an answer first
  3. 13foundation · easy

    When prioritizing remediation efforts using an SBOM, which factor is most important to consider?

    Select an answer first
  4. 14foundation · easy

    In a DevSecOps pipeline, where should SBOM generation be integrated?

    Select an answer first
  5. 15application · medium

    A software company builds a containerized Java application using a CI/CD pipeline. The security team needs an SBOM generated automatically for each build so that vulnerability scanning can occur before deployment. The team also wants the SBOM to include dependency relationships and license information. Which approach should the security architect recommend?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.