Objective 7.2
Cybersecurity Defense ArchitectExplain how a business’s risk tolerance informs a security program’s metrics
Objective 7.2 sits in Measuring and Improving Security Program Effectiveness, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A team lead asks what a measurement report should say about a finding besides the number. Which does NIST name?
Correct.
Checked against nvlpubs.nist.gov, August 2026Concept
A number without a tolerance invites either panic or complacency. Stating where it sits against appetite is what makes it a decision input.
Why D
NIST documents that a report could include any risk indicated by the measure and whether the findings fit in the organization's risk appetite.
Source
NIST SP 800-55 Volume 1: Measurement Guide for Information Security, checked August 2026Therefore, a report could include elements such as: • Any risk indicated by the measure • Whether the findings fit in the organization’s risk appetite • What prioritization, action, or decision might need to be taken
Now you: objective 7.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A team lead asks what NIST warns happens when a measure is reported without context. Which does SP 800-55 document?
Sample question 2 of 3
A team lead asks how NIST expects an organisation's risk appetite to shape CSF adoption. What does the CSF state?
Sample question 3 of 3
A team lead wants leadership to evaluate security trends over time. Which Enterprise Security dashboard does Splunk name?
Full Cybersecurity Defense Architect question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Measuring and Improving Security Program Effectiveness
- 7.1 Explain how to define, measure, and report on metrics to assess and monitor a security program’s effectiveness
- 7.3 Explain how Continuous Process Improvement can enrich and expand a metrics driven security program’s efficacy
- 7.4 Explain how security controls are continually tested and gaps are remediated