Splunk Certified Cybersecurity Defense Architect v1.0

Page:    1 / 8   
Exam contains 120 questions

A threat hunter is looking for suspicious login activity across multiple different authentication systems and cloud providers. Today, the threat hunter has to query multiple different data sources with unique logic to gather basic information about authentication events.
What method provides a simple way to standardize data formats, and look for common activity across different sources?

  • A. Risk-based alerting
  • B. Adaptive Response Actions
  • C. Calculated fields
  • D. Data normalization


Answer : D

A corporation chooses to engage in a Request for Information (RFI) / Request for Proposal (RFP) process.
What is a major advantage of this type of formal procurement process?

  • A. Standardizes vendor responses, making it easier to compare solutions against specific requirements.
  • B. Speeds up the time it takes to evaluate and stack rank solutions by only consulting third-party analyst rankings.
  • C. Allows vendors to provide bespoke responses based on a framework that highlights their capabilities best.
  • D. Eliminates significant amounts of internal paperwork and streamlines the evaluation process.


Answer : A

Buttercup Games needs to provide its SOC team access to a wide range of security data sources located across different regions and cloud providers.
Which architectural solution allows the SOC analysts to query these data sources as a single logical source without having to migrate or copy all the raw data?

  • A. Data mesh
  • B. Message bus
  • C. Centralized data warehouse
  • D. Federated search


Answer : D

An architect is consulting with an organization that requires data to be sent to various destination data stores based on a combination of criteria. This includes, but is not limited to, the presence of personally identifiable information (PII), specific key/value pairs in each event, and the required retention duration for specific data sources.
Which of the following types of technology would be most appropriate to address these requirements?

  • A. Data Vault
  • B. Data Router
  • C. Data Warehouse
  • D. Data Lake


Answer : B

A U.S. based company has recently purchased a German company. The U.S. organization is planning to consolidate their customer rewards program globally and begin collecting purchasing information on the German customers to send back to their U.S. data center.
Which data privacy law would they violate if they did not update the German End User Agreement?

  • A. FERPA
  • B. GDPR
  • C. HIPAA
  • D. CCPA


Answer : B

While working with the Security Automation team, an architect is reviewing a playbook that automates the handling of compromised credentials. The playbook contains the following stages:
Examine account to ensure that it is not a service or control account.
Access all identity platforms and lock the user account.
Revoke all current sessions (email, VPN, etc.).
The architect points out the potential for the compromised credentials to be used remotely again.
Which of the following actions need to be added to the playbook to alleviate this?

  • A. Revoke all users MFA tokens.
  • B. Create service desk ticket for the locked account.
  • C. Quarantine compromised users endpoint.
  • D. Revoke access to code repositories.


Answer : A

Danielle is a security architect at a multinational retail company. She is evaluating threat intelligence feeds to add to her company’s security monitoring program.
What is the primary benefit that threat intelligence data can provide?

  • A. Reduce long term data storage needs.
  • B. Enrich detections with internal asset information.
  • C. Add context to detection content.
  • D. Correlate user activity to security alerts.


Answer : C

Melinda’s team is responsible for maintaining detection content for a large organization. Her team consists of ten detection engineers, who need to log in to multiple SIEMs in order to make any changes to rules. Melinda wants to evaluate a “detection as code” methodology using the organization’s version control and continuous integration systems.
What benefits can detection as code provide her team? (Choose all that apply.)

  • A. Automated integration can reduce manual errors and speed up deployment.
  • B. Version control adds the ability to audit and rollback changes.
  • C. Security events can be triaged and closed more quickly.
  • D. Reusable components can reduce duplication and simplify rule writing.


Answer : ABD

Which of the following are key advantages of providing “paved road” security engineering templates? (Choose all that apply.)

  • A. They enable rapid onboarding of new projects by offering standardized, security-hardened infrastructure patterns.
  • B. They can integrate with CI/CD pipelines to ensure security and compliance checks are automated as part of the development workflow.
  • C. They eliminate the need for teams to perform any additional security reviews or testing after initial deployment.
  • D. They help enforce consistent security controls across diverse environments and reduce human error in manual configuration.


Answer : ABD

A new vulnerability has been announced in a software library. Leadership would like to understand what exposure this has caused.
What can be used to determine which vendor provided executables use that library?

  • A. Git file list
  • B. Vulnerability scan results
  • C. Release notes
  • D. Software Bill of Materials


Answer : D

The internet facing WAF for a new customer facing application has been identified as a potential telemetry collection point.
Which of the following best describes this data prior to any tuning or curation efforts?

  • A. High Value/Low Noise
  • B. High Value/High Noise
  • C. Low Value/High Noise
  • D. Low Value/Low Noise


Answer : B

An organization has decided to implement a new endpoint security product. The CISO has concerns about the rollout due to the nature of the varied endpoint builds and installed applications.
After initial testing in lab has shown no issues, what next step should the architect perform to ensure the success of their rollout?

  • A. Update all applications to their newest versions then perform testing.
  • B. Iterative testing in lab for each build and then each installed application.
  • C. Build new “golden” image for testing then deploy it to all hosts.
  • D. Test with subsets of users from each cross section of builds and applications.


Answer : D

Which of the following describes CIS controls?

  • A. A prioritized list of technical security controls that map to ISO standards
  • B. A collection of administrative security controls that map to NIST guidelines
  • C. A prioritized list of technical security controls that protect against the most common attack vectors
  • D. A collection of administrative and technical security controls that map to specific threat models


Answer : C

Kevin, a security architect, is planning a long-term retention strategy for security logs (e.g.7+ years) for compliance and forensic purposes.
Which storage solutions are cost-effective for this requirement and still allow future access? (Choose all that apply.)

  • A. Cloud object storage with infrequent access
  • B. SAN with cold storage tiers
  • C. SQL data warehouse
  • D. High performant SSD storage


Answer : AB

A critical legacy application server runs on an unsupported OS and IT cannot install a security agent or forward logs on this server. This application processes sensitive data.
What is the best strategy to continuously monitor the server’s activities?

  • A. Analyze network traffic via a tap.
  • B. Disconnect the application from the network.
  • C. Copy and review the access logs on a scheduled basis.
  • D. Install MCP Security Monitoring.


Answer : A

Page:    1 / 8   
Exam contains 120 questions

Talk to us!


Have any questions or issues ? Please dont hesitate to contact us

Certlibrary.com is owned by MBS Tech Limited: Room 1905 Nam Wo Hong Building, 148 Wing Lok Street, Sheung Wan, Hong Kong. Company registration number: 2310926
Certlibrary doesn't offer Real Microsoft Exam Questions. Certlibrary Materials do not contain actual questions and answers from Cisco's Certification Exams.
CFA Institute does not endorse, promote or warrant the accuracy or quality of Certlibrary. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.
Terms & Conditions | Privacy Policy | Amazon Exams | Cisco Exams | CompTIA Exams | Databricks Exams | Fortinet Exams | Google Exams | Microsoft Exams | VMware Exams