
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 2
Develop a Process to Manage, Coordinate, and Communicate Responses to Large-Scale Security Incidents. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
10%of the exam
Questions 1–5
- 1
What is the primary purpose of defining escalation paths in an incident response process?
Select an answer first - 2
An incident commander is preparing the final executive summary after a major incident has been resolved. The summary will be used to justify additional security investments to the board. The incident commander has access to the incident timeline, cost estimates, and lessons learned. Which information should be included to make the strongest case for additional investment?
Select an answer first - 3
An incident commander is preparing an executive summary for the board of directors after a significant security incident. The board is concerned about the financial impact and the company's reputation. The incident commander has access to detailed technical reports and the incident timeline. Which approach should be used to create the executive summary?
Select an answer first - 4
A healthcare organization is responding to a data breach that may involve protected health information. The incident response team has confirmed the breach and is preparing to notify affected patients, but the legal department has not yet completed its regulatory assessment. The CEO wants to send an immediate press release to reassure the public. Which communication action should the team take first?
Select an answer first - 5
An incident response team is documenting a large-scale incident that involved multiple waves of phishing attacks. The team has been using a shared document to record actions, but the document has become disorganized with duplicate entries and unclear statuses. The incident commander needs a clear picture of what has been done and what remains. Which documentation approach should the team implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.