Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 7Objective 2

Explain How a Businesss Risk Tolerance Informs a Security Programs Metrics. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)

Part of the Measuring and Improving Security Program Effectiveness domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts
15%of the exam

Questions 1–5

  1. 1expert · hard

    A hospital has a low risk tolerance for patient data breaches but a high risk tolerance for operational inefficiencies. The security team is evaluating two metrics: 'time to detect a breach' and 'number of security alerts per day.' The team has limited resources and can only report one metric to the board. Which metric should be reported?

    Select an answer first
  2. 2expert · hard

    A bank has a low risk tolerance for fraud but a high risk tolerance for minor service disruptions. The security team is defining metrics for the online banking platform. The team is considering two metrics: 'fraud loss as a percentage of transactions' and 'number of service interruptions per month.' The bank's board wants to see metrics that reflect the bank's risk tolerance. Which metric should be the primary focus?

    Select an answer first
  3. 3application · medium

    A financial services firm has a low risk tolerance for data breaches. The security team is setting a target for the metric 'time to contain a data breach.' Which target best reflects the firm's risk tolerance?

    Select an answer first
  4. 4application · medium

    A healthcare organization is setting a threshold for the metric 'percentage of endpoints with critical vulnerabilities patched within 7 days.' The organization has a low risk tolerance for ransomware and relies heavily on endpoint protection. Which threshold best reflects this risk tolerance?

    Select an answer first
  5. 5foundation · easy

    What is the key difference between risk appetite and risk tolerance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.