
SplunkCertified Cybersecurity Defense Architect
Domain 8Objective 1
Identify Organizational Coverage for Prevention, Detection, Response and Recovery Capabilities. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 6)
Part of the Security Capability Selection, Placement, Configuration domain, which accounts for 15% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
5concepts
15%of the exam
Questions 26–30
- 26
A media company's web application allows users to upload files. The security team is concerned about the risk of malicious file uploads leading to code execution on the server. Which control would most directly prevent this attack vector?
Select an answer first - 27
A financial institution has a well-documented incident response plan, but during a live ransomware exercise, the response team discovered that the plan did not specify how to handle the legal and regulatory reporting requirements for a data breach. The team was unsure whether to notify regulators before or after containing the incident. Which improvement would best address this response coverage gap?
Select an answer first - 28
A multinational organization has strong prevention controls (EDR, NGFW, email filtering) and comprehensive detection (SIEM, UEBA) for its corporate network. However, a recent audit revealed that its subsidiary in a high-risk region has no local security team and relies on the parent company's SOC, which only monitors during business hours in the parent's time zone. The subsidiary operates 24/7. Which combination of actions would best close the most critical coverage gaps?
Select an answer first - 29
Which activity is primarily associated with prevention coverage in a security architecture?
Select an answer first - 30
A bank's security operations center (SOC) relies on a SIEM that ingests logs from firewalls, servers, and endpoints. However, the SOC team is missing visibility into cloud infrastructure activity, such as changes to IAM policies or S3 bucket permissions. Which addition would most directly improve detection coverage for cloud-specific threats?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSECURITY-DEFENSE-ARCHITECT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.