
SplunkCertified Cybersecurity Defense Architect
Domain 3Objective 3
Ensure Appropriate Technologies and Processes Are in Place to Support Various Forensics Investigations. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)
Part of the Advanced Incident Response and Management domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
5concepts
10%of the exam
Questions 16–20
- 16
Which process is a key component of forensic readiness planning in a Splunk environment?
Select an answer first - 17
During an active incident, the incident response team needs to collect evidence from a compromised Linux host. The host is not currently forwarding logs to Splunk. The team must preserve the evidence in a forensically sound manner while minimizing the impact on the running system. What is the most appropriate first step?
Select an answer first - 18
A financial services company is preparing for potential regulatory investigations. The compliance team requires that any data used in a future forensic investigation be verifiably unaltered since collection. The Splunk environment currently stores all security logs in a standard index with default retention. What should the architect configure to meet this requirement?
Select an answer first - 19
A Splunk architect is designing a forensic readiness plan for an organization that must support multiple types of investigations. Which technology capability is most essential to include in the plan?
Select an answer first - 20
Which legal requirement is most directly supported by Splunk's ability to retain and search large volumes of log data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSECURITY-DEFENSE-ARCHITECT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.