Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 8Objective 2

Determine How Coverage Gaps Can Be Mitigated by Architecture Changes, Config Changes, or Process Changes. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 5)

Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
15%of the exam

Questions 21–25

  1. 21application · medium

    A Splunk deployment is missing coverage for detection of brute-force attacks on a VPN appliance. The VPN logs are being collected, but the correlation search for brute force is not firing. The architect discovers that the VPN logs use a non-standard timestamp format that Splunk is not parsing correctly. Which configuration change should the architect make?

    Select an answer first
  2. 22foundation · easy

    How can a process change mitigate a coverage gap in a Splunk deployment?

    Select an answer first
  3. 23foundation · easy

    When selecting a mitigation approach for a coverage gap, what is the key factor to consider?

    Select an answer first
  4. 24application · medium

    A Splunk architect is reviewing coverage for a new threat intelligence feed. The feed is being ingested and correlated, but the SOC is not acting on the alerts because the alerts are not integrated into the existing incident management workflow. Which mitigation approach best addresses this coverage gap?

    Select an answer first
  5. 25expert · hard

    A Splunk architect is designing a solution to close a coverage gap for network traffic analysis. The SOC needs to analyze NetFlow data, but the current forwarders are not capable of handling the volume. The architect must choose between deploying a dedicated NetFlow collector or using the existing indexers to process the data. The network team wants to minimize the number of new components. Which approach should the architect take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.