Objective 1.2

Cybersecurity Defense Analyst

Recognize common cyber industry controls, standards and frameworks and how Splunk incorporates those frameworks

Objective 1.2 sits in The Cyber Landscape, Frameworks, and Standards, which carries 10% of the Cybersecurity Defense Analyst exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-2The Cyber Landscape, Frameworks, and Standards

An analyst is asked how many Core Functions the NIST Cybersecurity Framework 2.0 defines. How many does NIST name?

SixCorrect · your answerCorrect.
FiveFive was the count before GOVERN was added in version 2.0.
FourFour is fewer than NIST lists.
SevenSeven is more than NIST lists.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

The function list is the framework's spine. Everything below it is a category of outcomes, so knowing the top level is what makes a mapping conversation possible.

Why A

NIST names GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER as the CSF Core Functions.

Source

The CSF Core Functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER — organize cybersecurity outcomes at their highest level.

NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0, checked August 2026
#nist csf#frameworks

Now you: objective 1.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-2The Cyber Landscape, Frameworks, and Standards

An analyst asks what the GOVERN function of NIST CSF 2.0 covers. What does NIST document?

Sample question 2 of 3

1-2The Cyber Landscape, Frameworks, and Standards

An analyst asks what the PROTECT function of NIST CSF 2.0 is for. What does NIST document?

Sample question 3 of 3

1-2The Cyber Landscape, Frameworks, and Standards

An analyst reads that Enterprise Security supports NIST, CIS and Critical Security Controls. Which further framework does Splunk name with them?

Full Cybersecurity Defense Analyst question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in The Cyber Landscape, Frameworks, and Standards