Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCertified Cybersecurity Defense Architect

Domain 4Objective 1

Understand How an Organizations Technical Architectures, E.g. Network Design, Enable or Constrain Security Orchestration. CYBERSECURITY-DEFENSE-ARCHITECT Practice Questions (Page 3)

Part of the Advanced Automation and Orchestration domain, which accounts for 10% of the CYBERSECURITY-DEFENSE-ARCHITECT exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)

15questions here
3free pages
5concepts
10%of the exam

Questions 11–15

  1. 11application · medium

    A security operations center (SOC) is deploying a SOAR platform that will automate responses across multiple security tools. The tools are distributed across different network zones, and the SOC wants to ensure that the SOAR platform can reliably reach all of them. Which network design approach best supports this requirement?

    Select an answer first
  2. 12foundation · easy

    A SOAR platform needs to integrate with an on-premises ticketing system that is only reachable through a NAT gateway. Which network topology feature is most likely to restrict the SOAR platform's ability to connect to the ticketing system?

    Select an answer first
  3. 13foundation · easy

    In a segmented network, a SOAR platform in the management zone needs to send a command to a firewall in the production zone. What network design element is most likely to constrain this orchestration action?

    Select an answer first
  4. 14foundation · easy

    An organization wants to deploy a SOAR platform that must integrate with tools in both on-premises and cloud environments. Which architectural factor is most important to assess for compatibility?

    Select an answer first
  5. 15application · medium

    A SOAR platform is configured to automatically disable a user's account in Active Directory when a phishing alert is confirmed. The SOAR platform is in a different network segment than the domain controllers. The SOAR platform can reach the domain controllers, but the account disable action fails. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CYBERSECURITY-DEFENSE-ARCHITECT” is a trademark of its owner, used for identification only.