
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 2
Develop a Process to Manage, Coordinate, and Communicate Responses to Large-Scale Security Incidents. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
10%of the exam
Questions 6–10
- 6
Which output is a typical result of a post-incident review?
Select an answer first - 7
A multinational company is responding to a supply-chain attack that has affected subsidiaries in different time zones. The SOC is in the US, IT teams are in Europe and Asia, and legal is based in the US. The incident commander needs to ensure that all teams are working from the same information and that decisions are made efficiently. Which coordination approach should be used?
Select an answer first - 8
What is the key to effective coordination across multiple teams during a large-scale security incident?
Select an answer first - 9
What is the main objective of a post-incident review?
Select an answer first - 10
What is the primary purpose of a communication plan during a large-scale security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.