Objective 6.3

Cybersecurity Defense Architect

Explain how industry standard security frameworks (PCI, HIPAA, OT/IC, others) affect cyber defense architecture

Objective 6.3 sits in Governance, Risk, and Compliance, which carries 10% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

6-3Governance, Risk, and Compliance

An administrator asks where the NIST control baselines now live after SP 800-53 Revision 5. What does NIST document?

In the CSF CoreThe CSF Core lists outcomes rather than baselines.
In SP 800-53 itselfRevision 5 holds the catalogue rather than the baselines.
In SP 800-37SP 800-37 describes the risk management framework.
In SP 800-53BCorrect · your answerCorrect.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

Separating the catalogue from the baselines lets one control set serve many regimes. Which document to hand an assessor depends on knowing the split.

Why D

NIST documents that the control baselines previously included in SP 800-53 have been relocated to SP 800-53B, which contains security and privacy control baselines.

Source

The control baselines that have previously been included in NIST Special Publication 800-53 have been relocated to NIST Special Publication 800-53B.

NIST SP 800-53 Revision 5: Security and Privacy Controls, checked August 2026
#compliance#controls

Now you: objective 6.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

6-3Governance, Risk, and Compliance

An administrator must adapt a baseline to a sector's requirements. Which two mechanisms does NIST name for that?

Sample question 2 of 2

6-3Governance, Risk, and Compliance

An administrator works on a national security system and asks which instruction supplies its baselines. Which does NIST name?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Governance, Risk, and Compliance