Objective 3.1

Cybersecurity Defense Architect

Align cybersecurity incident response with an organization’s incident management, change management, and other ITSM/ITIL processes

Objective 3.1 sits in Advanced Incident Response and Management, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-1Advanced Incident Response and Management

A team lead asks how NIST now positions incident response relative to the rest of the organisation. What does SP 800-61r3 state?

It is integrated across operationsCorrect · your answerCorrect.
It should be a separate functionKeeping it separate is the model NIST moved away from.
It should sit under IT operationsNIST places it in risk management rather than under one department.
It should be outsourced entirelyThird parties may assist, but the guidance is not to outsource wholesale.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

Treating response as a separate activity worked when incidents were rare and short. Integration is what lets governance and prevention learn from what response finds.

Why A

NIST documents that incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations.

Source

Incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations.

NIST SP 800-61r3: Incident Response Recommendations and Considerations for Cyber Risk Management, checked August 2026
#incident response#integration

Now you: objective 3.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-1Advanced Incident Response and Management

A team lead asks which CSF Functions NIST places in incident response itself. Which set does SP 800-61r3 name?

Sample question 2 of 3

3-1Advanced Incident Response and Management

A team lead asks when lessons learned should be shared under NIST guidance. What does SP 800-61r3 state?

Sample question 3 of 3

3-1Advanced Incident Response and Management

A team lead asks how NIST treats the choice of incident response life cycle model. What does SP 800-61r3 state?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Advanced Incident Response and Management