Objective 5.3

Cybersecurity Defense Architect

Describe how to create and leverage a SBOM (Software Bill of Materials) in cybersecurity defenses

Objective 5.3 sits in Scaling Cybersecurity Defenses and DevSecOps, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

5-3Scaling Cybersecurity Defenses and DevSecOps

An engineer is asked to define an SBOM for a supply chain programme. Which definition does the NTIA report give?

A formal record of componentsCorrect · your answerCorrect.
A list of approved vendorsA vendor list names suppliers rather than components.
A scan of running processesRuntime scanning observes behaviour rather than composition.
A register of open incidentsAn incident register tracks events rather than software content.

Correct.

Checked against ntia.gov, August 2026

Concept

An inventory of what is inside a product is what turns a new vulnerability advisory into a search rather than a survey. Nothing else answers the question quickly.

Why A

The NTIA report defines an SBOM as a formal record containing the details and supply chain relationships of various components used in building software.

Source

An SBOM is a formal record containing the details and supply chain relationships of various components used in building software.

NTIA: The Minimum Elements For a Software Bill of Materials (SBOM), checked August 2026
#sbom#supply chain

Now you: objective 5.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

5-3Scaling Cybersecurity Defenses and DevSecOps

An engineer asks which three areas the SBOM minimum elements comprise. Which set does NTIA name?

Sample question 2 of 3

5-3Scaling Cybersecurity Defenses and DevSecOps

An engineer asks which baseline data fields NTIA says should be tracked for each SBOM component. Which is on the documented list?

Sample question 3 of 3

5-3Scaling Cybersecurity Defenses and DevSecOps

An architect asks what benefit the NTIA report names as most notable from SBOM adoption. Which is documented?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Scaling Cybersecurity Defenses and DevSecOps