
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 2
Develop a Process to Manage, Coordinate, and Communicate Responses to Large-Scale Security Incidents. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 6)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
6concepts
10%of the exam
Questions 26–30
- 26
During a large-scale incident, the incident response team is documenting actions in real time. However, the documentation is incomplete because some team members are too busy to log their actions immediately. The incident commander needs a complete and accurate record for the post-incident review. Which strategy should be implemented to ensure documentation is not neglected?
Select an answer first - 27
A post-incident review is being conducted after a major security incident. The review team includes members from the SOC, IT, legal, and executive stakeholders. The SOC believes the incident was handled well, but IT argues that the response was too aggressive and disrupted business operations. The incident commander must facilitate a review that leads to meaningful improvements. Which approach should be taken?
Select an answer first - 28
Which component is essential in a structured incident response process for large-scale security incidents?
Select an answer first - 29
A large financial services firm has just activated its incident response plan for a suspected ransomware outbreak affecting multiple business units. The SOC lead has been designated as the incident commander, but the legal team is demanding direct control over all external communications, and the IT director insists on approving every containment action. The response is stalling because team members are receiving conflicting instructions. Which action should the incident commander take first to restore momentum?
Select an answer first - 30
During a large-scale incident, the incident commander is coordinating the response across the SOC, IT, legal, and executive teams. The SOC is focused on containment, IT is concerned about business continuity, and legal is worried about regulatory compliance. The incident commander must ensure that all teams work together effectively. Which coordination strategy should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSECURITY-DEFENSE-ARCHITECT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.