
SplunkCertified Cybersecurity Defense Architect
Domain 8Objective 1
Identify Organizational Coverage for Prevention, Detection, Response and Recovery Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 4)
Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
5concepts
15%of the exam
Questions 16–20
- 16
A law firm uses a cloud-based document management system (DMS) and is concerned about the risk of data exfiltration via compromised user accounts. The firm wants to prevent unauthorized downloads of sensitive client documents. Which control would most directly address this prevention gap?
Select an answer first - 17
A utility company has monitoring for its corporate IT network but lacks visibility into its operational technology (OT) environment, which uses legacy protocols like Modbus. The security team wants to detect anomalies in OT network traffic that could indicate a cyber-physical attack. Which addition would most directly improve detection coverage for the OT environment?
Select an answer first - 18
Which component is most directly part of recovery coverage?
Select an answer first - 19
A financial services firm has deployed a next-generation firewall (NGFW) at the internet perimeter, endpoint detection and response (EDR) on all laptops, and a web application firewall (WAF) in front of its customer portal. The security team is mapping coverage against the MITRE ATT&CK framework and notices that the 'Initial Access' technique T1190 (Exploit Public-Facing Application) is well covered, but the 'Lateral Movement' technique T1021 (Remote Services) is not explicitly addressed by any control. Which additional control would most directly close this prevention gap?
Select an answer first - 20
A telecommunications company has incident response playbooks for network outages and malware infections, but during a recent data breach, the response team was unsure how to coordinate with legal, PR, and law enforcement. Which improvement would most directly address this response coverage gap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.