Objective 3.3

Cybersecurity Defense Architect

Ensure appropriate technologies and processes are in place to support various forensics investigations

Objective 3.3 sits in Advanced Incident Response and Management, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

3-3Advanced Incident Response and Management

A team lead needs analysts to reconstruct what a detection saw during a forensic review. Which Enterprise Security feature does Splunk document for that?

Adaptive response throttlesThrottling limits how often response actions fire.
Notable event suppressionsSuppression hides notables from the review queue.
Contributing events searchesCorrect · your answerCorrect.
Key indicator searchesKey indicator searches populate dashboard metrics.

Correct.

Checked against help.splunk.com, August 2026

Concept

A finding that cannot be traced back to its evidence is unusable in a forensic account. Preserving the path from alert to raw event is an architectural requirement.

Why C

Splunk documents that expanding a risk event on the Risk Timeline displays a Contributing Events search based on the original correlation search that generated the risk event.

Source

Visualizations such as Threat Topology and Risk Event Timeline allow analysts to quickly visualize relationships between malicious threat actors and their users and systems when working with findings.

Splunk Docs: Analyze risk with risk-based alerting in Splunk Enterprise Security, checked August 2026
#forensics#investigation

Now you: objective 3.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

3-3Advanced Incident Response and Management

A team lead wants investigations to span weeks rather than a single alert. Which capability does Splunk document risk-based alerting providing?

Sample question 2 of 3

3-3Advanced Incident Response and Management

A team lead asks which frameworks Enterprise Security supports for classifying an incident during review. Which does Splunk name alongside MITRE ATT&CK?

Sample question 3 of 3

3-3Advanced Incident Response and Management

An architect asks what the AI Assistant returns when asked to summarise an investigation. Which set does Splunk document?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Advanced Incident Response and Management