Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 3Objective 3

Ensure Appropriate Technologies and Processes Are in Place to Support Various Forensics Investigations. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)

Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
5concepts
10%of the exam

Questions 16–20

  1. 16foundation · easy

    Which process is a key component of forensic readiness planning in a Splunk environment?

    Select an answer first
  2. 17application · medium

    During an active incident, the incident response team needs to collect evidence from a compromised Linux host. The host is not currently forwarding logs to Splunk. The team must preserve the evidence in a forensically sound manner while minimizing the impact on the running system. What is the most appropriate first step?

    Select an answer first
  3. 18application · medium

    A financial services company is preparing for potential regulatory investigations. The compliance team requires that any data used in a future forensic investigation be verifiably unaltered since collection. The Splunk environment currently stores all security logs in a standard index with default retention. What should the architect configure to meet this requirement?

    Select an answer first
  4. 19foundation · easy

    A Splunk architect is designing a forensic readiness plan for an organization that must support multiple types of investigations. Which technology capability is most essential to include in the plan?

    Select an answer first
  5. 20foundation · easy

    Which legal requirement is most directly supported by Splunk's ability to retain and search large volumes of log data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.