
SplunkCertified Cybersecurity Defense Architect
Domain 5Objective 2
Describe How to Integrate Security Sensors and Controls into DevOps Workflows. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)
Part of the Scaling Cybersecurity Defenses and DevSecOps domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
4concepts
15%of the exam
Questions 6–10
- 6
How are security controls automated in DevOps workflows to enforce policies?
Select an answer first - 7
A company has implemented a DAST tool that runs against a staging environment. The tool is generating a large number of alerts, and the development team is overwhelmed. The security team wants to prioritize the alerts so the developers can focus on the most critical issues first. What is the most effective way to prioritize the DAST findings?
Select an answer first - 8
A large enterprise is implementing a DevSecOps strategy. They have a mix of legacy applications that are deployed manually and new cloud-native applications that use a full CI/CD pipeline. The security team has limited resources and cannot manually review every change. They need to enforce a policy that no critical vulnerabilities are present in production. Which approach best balances the need for security enforcement with the reality of the mixed environment?
Select an answer first - 9
A DevOps team wants to automatically block a deployment if a critical vulnerability is found in the application's dependencies. The team uses a CI/CD pipeline with separate build, test, and deploy stages. What is the most appropriate way to automate this security control?
Select an answer first - 10
A company is moving from a waterfall to a DevOps model. The security team wants to ensure that security is considered throughout the development lifecycle, not just at the end. Which approach best reflects this shift?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.