
SplunkCertified Cybersecurity Defense Architect
Domain 7Objective 1
Explain How to Define, Measure, and Report on Metrics to Assess and Monitor a Security Programs Effectiveness. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 5)
Part of the Measuring and Improving Security Program Effectiveness domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
15%of the exam
Questions 21–25
- 21
A security team monitors the percentage of endpoints with the latest antivirus signatures. The metric has been stable at 98% for six months. The team wants to identify areas for improvement. What is the most appropriate next step?
Select an answer first - 22
A security team wants to measure the percentage of phishing emails reported by users. They have access to email gateway logs and user-reported phishing simulations. Which data source is most appropriate for this metric?
Select an answer first - 23
What is the role of benchmarks and targets in assessing security program effectiveness?
Select an answer first - 24
Which data source is most appropriate for measuring the metric 'mean time to detect (MTTD) a security incident'?
Select an answer first - 25
A security analyst must report on the effectiveness of the patch management program to the IT operations manager, who is responsible for system availability. Which metric is most relevant to this stakeholder?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.