
SplunkCertified Cybersecurity Defense Architect
Domain 8Objective 2
Determine How Coverage Gaps Can Be Mitigated by Architecture Changes, Config Changes, or Process Changes. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)
Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
15%of the exam
Questions 16–20
- 16
A Splunk architect is reviewing coverage for a new compliance requirement that mandates monitoring of all administrative actions on a critical database. The database logs are already being collected, but the SOC is not seeing any alerts for unauthorized administrative changes. The architect suspects the logs are not being parsed correctly. Which configuration change should the architect make first?
Select an answer first - 17
A Splunk architect is reviewing coverage for a new regulation that requires monitoring of all access to customer data. The application logs are being collected, but the SOC is overwhelmed by the volume of alerts and is missing critical alerts. The architect determines that the correlation searches are too broad. Which mitigation approach best addresses this coverage gap?
Select an answer first - 18
A Splunk deployment is missing coverage for detection of data exfiltration via DNS. The SOC has access to DNS logs, but they are not being collected. The network team is concerned about the additional load on the DNS servers if a forwarder is installed. Which mitigation approach best addresses this coverage gap while minimizing the impact on the DNS servers?
Select an answer first - 19
How can a configuration change mitigate a coverage gap in a Splunk deployment?
Select an answer first - 20
A Splunk deployment is missing coverage for encrypted traffic analysis. The SOC wants to detect malicious TLS certificates, but the current forwarders only collect firewall logs. The network team is concerned about the performance impact of decrypting traffic at the firewall. Which architecture change would best mitigate this coverage gap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.