
SplunkCertified Cybersecurity Defense Architect
Domain 7Objective 1
Explain How to Define, Measure, and Report on Metrics to Assess and Monitor a Security Programs Effectiveness. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)
Part of the Measuring and Improving Security Program Effectiveness domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
15%of the exam
Questions 16–20
- 16
A security team is assessing the effectiveness of their vulnerability management program. They have two metrics: percentage of critical vulnerabilities remediated within 30 days (currently 85%) and percentage of critical vulnerabilities remediated within 60 days (currently 95%). The target for both is 90%. Which conclusion is most appropriate?
Select an answer first - 17
What is the primary purpose of reporting security metrics to stakeholders?
Select an answer first - 18
A security team monitors the mean time to respond (MTTR) to incidents. Over the last six months, MTTR has decreased from 4 hours to 2 hours, but the number of incidents has increased. What is the most appropriate interpretation of these trends?
Select an answer first - 19
A security architect is defining metrics for a new security program. Which action best ensures the metrics align with the organization's security goals?
Select an answer first - 20
A security operations center (SOC) wants to measure the average time to detect (MTTD) security incidents. They have access to multiple data sources. Which data source provides the most reliable and accurate basis for this metric?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.