Objective 2.1

Cybersecurity Defense Architect

Explain how to develop and implement integration strategies for data-driven security operations

Objective 2.1 sits in Security Data Management, which carries 20% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

2-1Security Data Management

An engineer asks what log management covers as a process. Which set does NIST document?

Collecting and searching onlyCollection and search are two stages of the five named.
Generating through to disposingCorrect · your answerCorrect.
Indexing and alerting onlyIndexing and alerting are platform functions rather than the process.
Archiving and restoring onlyArchiving sits inside the storage and disposal stages.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

Naming the whole chain is what stops a design that collects well and disposes badly. Every stage is somewhere a requirement can be missed.

Why B

NIST documents log management as the process for generating, transmitting, storing, accessing and disposing of log data.

Source

Log management is the process for generating, transmitting, storing, accessing, and disposing of log data.

NIST SP 800-92r1 (initial public draft): Cybersecurity Log Management Planning Guide, checked August 2026
#log management#strategy

Now you: objective 2.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

2-1Security Data Management

An engineer asks what NIST says log management facilitates beyond security. Which purpose is documented?

Sample question 2 of 2

2-1Security Data Management

An engineer asks how NIST defines a log for planning purposes. Which definition is documented?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Data Management