Objective 3.3
Cybersecurity Defense ArchitectEnsure appropriate technologies and processes are in place to support various forensics investigations
Objective 3.3 sits in Advanced Incident Response and Management, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A team lead needs analysts to reconstruct what a detection saw during a forensic review. Which Enterprise Security feature does Splunk document for that?
Correct.
Checked against help.splunk.com, August 2026Concept
A finding that cannot be traced back to its evidence is unusable in a forensic account. Preserving the path from alert to raw event is an architectural requirement.
Why C
Splunk documents that expanding a risk event on the Risk Timeline displays a Contributing Events search based on the original correlation search that generated the risk event.
Source
Splunk Docs: Analyze risk with risk-based alerting in Splunk Enterprise Security, checked August 2026Visualizations such as Threat Topology and Risk Event Timeline allow analysts to quickly visualize relationships between malicious threat actors and their users and systems when working with findings.
Now you: objective 3.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A team lead wants investigations to span weeks rather than a single alert. Which capability does Splunk document risk-based alerting providing?
Sample question 2 of 3
A team lead asks which frameworks Enterprise Security supports for classifying an incident during review. Which does Splunk name alongside MITRE ATT&CK?
Sample question 3 of 3
An architect asks what the AI Assistant returns when asked to summarise an investigation. Which set does Splunk document?
Full Cybersecurity Defense Architect question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.