Objective 3.2

Cybersecurity Defense Architect

Develop a process to manage, coordinate, and communicate responses to large-scale security incidents

Objective 3.2 sits in Advanced Incident Response and Management, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-2Advanced Incident Response and Management

A team lead defines who may authorise shutting down a critical service during an incident. Which role does NIST name?

Third partiesThird parties may perform activities under contract.
Incident handlersHandlers perform the response work itself.
Legal counselLegal advises where an incident has legal ramifications.
LeadershipCorrect · your answerCorrect.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

A decision with business consequences needs an owner with business authority. Naming that owner in advance is what stops a containment decision stalling at 3am.

Why D

NIST documents that the leadership team oversees incident response, allocates funding, and may have decision-making authority on high-impact response actions such as shutting down or rebuilding critical services.

Source

Leadership. The organization's leadership team oversees incident response, allocates funding, and may have decision-making authority on high-impact response actions, such as shutting down or rebuilding critical services.

NIST SP 800-61r3: Incident Response Recommendations and Considerations for Cyber Risk Management, checked August 2026
#incident response#roles

Now you: objective 3.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-2Advanced Incident Response and Management

An architect asks how NIST expects roles and responsibilities to vary. What does SP 800-61r3 state?

Sample question 2 of 3

3-2Advanced Incident Response and Management

A team lead asks which third parties NIST names as sometimes filling a primary response role. Which is documented?

Sample question 3 of 3

3-2Advanced Incident Response and Management

A team lead asks when NIST says an incident responder should seek guidance from the legal department. What does SP 800-61r3 state?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Advanced Incident Response and Management