Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 6Objective 2

Explain How Regulations Like GDPR Affect Cyber Defense Architecture in Relation to Data Privacy Impact on Logging, Data Sovereignty, and Data Residency. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Governance, Risk, and Compliance domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
5concepts
10%of the exam

Questions 11–15

  1. 11application · medium

    A European e-commerce company's SIEM currently logs full HTTP request URLs, including query strings that contain session tokens and customer IDs. The security team needs to detect SQL injection attempts, which are visible in the URL. The DPO has required the company to minimize personal data in logs. What should the security architect implement?

    Select an answer first
  2. 12expert · hard

    A German manufacturing company's SIEM logs all network traffic metadata, including source and destination IPs, ports, and protocol. The company's DPO has determined that IP addresses are personal data in this context. The security team needs to detect lateral movement, which requires correlating IP addresses across the network. The DPO has mandated data minimization. What is the most balanced architectural approach?

    Select an answer first
  3. 13application · medium

    A Portuguese retail chain's SIEM stores logs of customer transactions. A data subject has requested that their personal data be erased. The security team has identified the relevant logs, but the legal team has determined that the company is legally required to retain certain transaction data for tax purposes for 10 years. What should the security architect do?

    Select an answer first
  4. 14application · medium

    A Dutch healthcare organization is designing a new SIEM. The organization treats patients in the Netherlands only, and the Dutch data protection authority requires that health data be stored within the EU. The security team wants to use a cloud SIEM that offers regions in the EU, the US, and Asia. The SIEM will ingest logs from patient management systems. Which deployment decision best satisfies the data residency requirement?

    Select an answer first
  5. 15expert · hard

    A Belgian bank's SIEM logs all customer transaction data for fraud detection. A data subject has requested access to their personal data. The security team has identified the relevant logs, but the logs also contain the transaction data of other customers. The bank's legal team has confirmed that the request is valid. What should the security architect ensure happens?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.