Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 7Objective 3

Explain How Continuous Process Improvement Can Enrich and Expand a Metrics Driven Security Programs Efficacy. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 2)

Part of the Measuring and Improving Security Program Effectiveness domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
5concepts
15%of the exam

Questions 6–10

  1. 6expert · hard

    A security team has a mature metrics program, but the CISO is concerned that the team is 'improving the metrics' rather than 'improving security'. The team has been optimizing for metrics like low false positive rates and fast response times, but security incidents have not decreased. How can CPI help refocus the program on actual security outcomes?

    Select an answer first
  2. 7application · medium

    A security team has been using the PDCA cycle to improve its incident response process. After several cycles, the mean time to respond (MTTR) has plateaued. The team is considering whether to continue with the current approach or try something new. What is the most CPI-aligned action?

    Select an answer first
  3. 8foundation · easy

    A security team notices that the mean time to detect (MTTD) incidents has been steadily increasing over the past three months. According to CPI principles, what is the most appropriate next step?

    Select an answer first
  4. 9expert · hard

    A security team is using PDCA to improve its detection capabilities. In the 'Check' phase, they find that the number of alerts has increased, but the false positive rate has also increased. The team is considering whether to tune the detection rules or to add more analysts. What should the team do first, according to CPI?

    Select an answer first
  5. 10application · medium

    A security team wants to align its metrics with the organization's strategic goal of reducing cyber risk. Currently, the team tracks operational metrics like firewall rule changes and antivirus update success rates. How can CPI help the team better align its metrics with the strategic goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.