Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 8Objective 1

Identify Organizational Coverage for Prevention, Detection, Response and Recovery Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
5concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A healthcare organization has monitoring in place for its email gateway, endpoint devices, and cloud workloads, but it lacks visibility into its on-premises legacy database servers. The security team is assessing detection coverage and wants to ensure that suspicious queries and unauthorized access attempts against these databases are identified. Which action would most effectively improve detection coverage for this environment?

    Select an answer first
  2. 12expert · hard

    A hospital's incident response plan includes a detailed playbook for ransomware, but during a real attack, the IT team discovered that the playbook did not specify how to prioritize the restoration of critical patient care systems over administrative systems. The result was a delayed recovery of life-sustaining equipment. Which improvement would best address this response and recovery gap?

    Select an answer first
  3. 13foundation · easy

    Which element is most directly part of response coverage?

    Select an answer first
  4. 14expert · hard

    A hospital's backup strategy includes nightly full backups to a local NAS and weekly off-site backups to a cloud provider. During a ransomware attack, the hospital discovered that the local NAS was encrypted and the cloud backups were not accessible because the cloud account credentials were also compromised. The hospital wants to ensure that backups remain recoverable even if both primary and secondary backup locations are compromised. Which action would best address this recovery gap?

    Select an answer first
  5. 15application · medium

    A manufacturing company has incident response playbooks for malware outbreaks and phishing campaigns, but during a recent ransomware simulation, the response team struggled to coordinate containment actions across IT and OT environments. The team realized that the playbook did not specify who has authority to disconnect OT systems from the network. Which improvement would most directly address this response coverage gap?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.