Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 6Objective 2

Explain How Regulations Like GDPR Affect Cyber Defense Architecture in Relation to Data Privacy Impact on Logging, Data Sovereignty, and Data Residency. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 1)

Part of the Governance, Risk, and Compliance domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
5concepts
10%of the exam

Questions 1–5

  1. 1application · medium

    An Italian insurance company's security team is deploying a new SIEM. The company has customers in Italy only, and the Italian data protection authority requires that personal data be stored within the EU. The SIEM vendor offers a multi-region deployment with automatic failover. The security architect is concerned about the failover feature. What should the architect configure to ensure data residency is maintained?

    Select an answer first
  2. 2expert · hard

    A Dutch hospital's SIEM logs patient access events, including the patient ID, the staff member who accessed the record, and the timestamp. The hospital's DPO has mandated a 6-month retention period for these logs. The security team has discovered that a ransomware investigation requires logs from 8 months ago. The logs have already been deleted. What should the security architect implement to prevent this situation in the future?

    Select an answer first
  3. 3application · medium

    A multinational retailer's SIEM ingests raw authentication logs from point-of-sale systems across EU stores. The logs contain the full name, email address, and purchase history of customers who used loyalty cards at the register. The DPO has flagged that the SIEM stores these logs for 24 months, but the loyalty program's purpose-limitation notice states customer purchase data is only processed for 6 months. The security team needs to keep the logs for threat detection. What should the security architect configure to satisfy GDPR while preserving detection capability?

    Select an answer first
  4. 4foundation · easy

    According to GDPR's purpose limitation principle, how should security logs containing personal data be handled?

    Select an answer first
  5. 5foundation · easy

    What does 'data sovereignty' mean in the context of GDPR?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.