
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 3
Ensure Appropriate Technologies and Processes Are in Place to Support Various Forensics Investigations. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
5concepts
10%of the exam
Questions 11–15
- 11
When collecting digital evidence from Splunk for a forensic investigation, what is the primary purpose of documenting the chain of custody?
Select an answer first - 12
A company is implementing forensic readiness and needs to ensure that the Splunk environment can support investigations that require high-fidelity data. The current setup uses a single index for all data with a 30-day retention. The investigation team often needs data that is older than 30 days. What is the most effective way to improve the environment?
Select an answer first - 13
A legal hold has been placed on a user's data due to an ongoing lawsuit. The data is stored in Splunk. The architect needs to ensure that this data is not deleted by the standard retention policy. What is the most appropriate action?
Select an answer first - 14
A global company is subject to both GDPR and CCPA. They are designing a forensic investigation process that involves collecting personal data from Splunk logs. The legal team is concerned about cross-border data transfers. What is the most important factor to address in the process design?
Select an answer first - 15
During a data breach investigation, the legal team requires that evidence be collected in a way that maintains a clear chain of custody. The evidence includes logs from a critical database server that is still in production. The team cannot take the server offline. What is the most appropriate method to collect the logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.