Objective 6.2

Cybersecurity Defense Architect

Explain how regulations like GDPR affect cyber defense architecture in relation to data privacy impact on logging, data sovereignty, and data residency

Objective 6.2 sits in Governance, Risk, and Compliance, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

6-2Governance, Risk, and Compliance

An administrator designs log retention for systems holding personal data. Which GDPR principle governs how long records may identify a person?

Data minimisationData minimisation limits how much is collected.
Purpose limitationPurpose limitation governs what the data may be used for.
Storage limitationCorrect · your answerCorrect.
AccuracyAccuracy requires data to be kept up to date.

Correct.

Checked against eur-lex.europa.eu, August 2026

Concept

A retention period set only by security need will collide with privacy law. Naming the principle is what makes the conversation with a data protection officer productive.

Why C

The GDPR requires personal data to be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed.

Source

kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed

EUR-Lex: Regulation (EU) 2016/679, the General Data Protection Regulation, checked August 2026
#privacy#gdpr

Now you: objective 6.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

6-2Governance, Risk, and Compliance

An administrator proposes collecting every field a log source offers. Which GDPR principle constrains that?

Sample question 2 of 3

6-2Governance, Risk, and Compliance

An architect wants to keep security logs beyond their original purpose. Which GDPR provision does the regulation attach to that?

Sample question 3 of 3

6-2Governance, Risk, and Compliance

An administrator asks what safeguard the GDPR names as an example when processing data for archiving purposes. Which is documented?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Governance, Risk, and Compliance