Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 4Objective 2

Develop Complex/cross Platform Automation to Orchestrate Workflows for Cybersecurity Operations Such as Investigation, Detection, and Incident Response. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 5)

Part of the Advanced Automation and Orchestration domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts
10%of the exam

Questions 21–25

  1. 21foundation · easy

    What is the primary function of automated detection mechanisms in cybersecurity?

    Select an answer first
  2. 22expert · hard

    A company uses Splunk to detect a specific malware signature. The detection rule is known to produce occasional false positives. When the rule fires, a SOAR playbook automatically quarantines the affected endpoint. The security team is concerned that false positives are causing unnecessary quarantines, which disrupt users. They want to reduce false-positive quarantines without completely disabling automation. Which approach is most effective?

    Select an answer first
  3. 23application · medium

    An automated detection workflow in Splunk triggers a SOAR playbook that queries an external threat intelligence API. The API occasionally returns a 429 (rate limit) or 503 (service unavailable) error. The playbook must continue processing other alerts while waiting for the API to recover, and it must not lose the alert data. Which error-handling strategy is most appropriate?

    Select an answer first
  4. 24expert · hard

    A security team is building a SOAR playbook that automatically disables user accounts and resets passwords in response to a confirmed insider threat. The compliance team requires that all actions be logged with the identity of the analyst who triggered the playbook, and that the playbook cannot be modified by unauthorized users. The team also wants to ensure that if the playbook fails mid-execution, the logs are still preserved. Which combination of controls is most appropriate?

    Select an answer first
  5. 25application · medium

    A SOAR platform is used to automate incident response actions, including disabling user accounts and blocking IPs. The compliance team requires that every automated action be traceable to the analyst who initiated it and that the action cannot be modified after execution. Which configuration is essential to meet this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.