Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 3Objective 2

Develop a Process to Manage, Coordinate, and Communicate Responses to Large-Scale Security Incidents. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts
10%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst is documenting a large-scale incident. The analyst has been recording actions in a shared spreadsheet, but several entries are missing timestamps and some actions were performed by multiple team members without clear attribution. The incident commander needs an accurate timeline for the post-incident review. Which documentation practice should the analyst adopt?

    Select an answer first
  2. 12application · medium

    After containing a significant phishing campaign that compromised several user accounts, the incident response team is conducting a post-incident review. The team identifies that the detection rule failed to trigger because it relied on a single indicator that was easily bypassed. Which outcome should the review produce?

    Select an answer first
  3. 13foundation · easy

    Which practice best supports collaboration between the SOC and legal teams during an incident?

    Select an answer first
  4. 14expert · hard

    A company is responding to a security incident that has attracted media attention. The CEO wants to provide regular public updates, but the legal team is concerned about revealing sensitive information that could be used against the company. The incident commander must develop a communication plan that satisfies the CEO's desire for transparency while protecting the company's legal position. Which communication approach should be adopted?

    Select an answer first
  5. 15foundation · easy

    Which of the following should be included in incident documentation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.