Objective 5.3
Cybersecurity Defense ArchitectDescribe how to create and leverage a SBOM (Software Bill of Materials) in cybersecurity defenses
Objective 5.3 sits in Scaling Cybersecurity Defenses and DevSecOps, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An engineer is asked to define an SBOM for a supply chain programme. Which definition does the NTIA report give?
Correct.
Checked against ntia.gov, August 2026Concept
An inventory of what is inside a product is what turns a new vulnerability advisory into a search rather than a survey. Nothing else answers the question quickly.
Why A
The NTIA report defines an SBOM as a formal record containing the details and supply chain relationships of various components used in building software.
Source
NTIA: The Minimum Elements For a Software Bill of Materials (SBOM), checked August 2026An SBOM is a formal record containing the details and supply chain relationships of various components used in building software.
Now you: objective 5.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An engineer asks which three areas the SBOM minimum elements comprise. Which set does NTIA name?
Sample question 2 of 3
An engineer asks which baseline data fields NTIA says should be tracked for each SBOM component. Which is on the documented list?
Sample question 3 of 3
An architect asks what benefit the NTIA report names as most notable from SBOM adoption. Which is documented?
Full Cybersecurity Defense Architect question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Scaling Cybersecurity Defenses and DevSecOps
- 5.1 Develop scalable strategies for agile and DevOps-driven cybersecurity defenses, such as detection as code
- 5.2 Describe how to integrate security sensors and controls into DevOps workflows. -
- 5.4 Describe continuous integration & deployment strategies for security data management and engineering solutions