Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 3Objective 2

Develop a Process to Manage, Coordinate, and Communicate Responses to Large-Scale Security Incidents. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts
10%of the exam

Questions 16–20

  1. 16application · medium

    During a ransomware incident, the incident response team has confirmed that customer data was exfiltrated. The CEO wants to inform customers immediately, but the legal team advises waiting until the investigation is complete to avoid inaccurate statements. The incident commander must balance transparency with legal risk. Which communication strategy should be adopted?

    Select an answer first
  2. 17expert · hard

    A company is developing an incident response process for large-scale incidents. The company has a small SOC team and relies on external vendors for specialized forensics. The process must ensure that the SOC can coordinate with external vendors while maintaining control over the response. Which process design should be implemented?

    Select an answer first
  3. 18foundation · easy

    What is the primary goal of an executive summary during an incident?

    Select an answer first
  4. 19expert · hard

    A large organization is designing its incident response process for large-scale incidents. The SOC is staffed 24/7, but the legal and executive teams are only available during business hours. The organization must ensure that critical decisions can be made at any time without violating legal or regulatory requirements. Which process design should be implemented?

    Select an answer first
  5. 20expert · hard

    A global company is responding to a data breach that affects customers in multiple countries with different data protection regulations. The communication team wants to send a single global message to all affected customers, but legal has advised that notification requirements differ by jurisdiction. The incident commander must develop a communication plan that satisfies all legal obligations while maintaining a consistent brand message. Which approach should be taken?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.