Objective 8.1

Cybersecurity Defense Architect

Identify organizational coverage for prevention, detection, response and recovery capabilities

Objective 8.1 sits in Security Capability Selection, Placement, Configuration, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

8-1Security Capability Selection, Placement, Configuration

An administrator maps organisational coverage using the CSF. What does NIST document the DETECT Function as covering?

Containing incident effectsContainment is part of RESPOND.
Restoring affected operationsRestoration is the RECOVER Function.
Establishing risk policyPolicy is established under GOVERN.
Finding and analysing attacksCorrect · your answerCorrect.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

Assigning each capability to one function is what turns an estate into a coverage map. Overlap is fine; a function with nothing in it is the finding.

Why D

NIST documents DETECT as where possible cybersecurity attacks and compromises are found and analyzed, enabling timely discovery and analysis of anomalies and indicators of compromise.

Source

DETECT (DE) - Possible cybersecurity attacks and compromises are found and analyzed. DETECT enables the timely discovery and analysis of anomalies, indicators of compromise, and other potentially adverse events that may indicate that cybersecurity attacks and incidents are occurring.

NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0, checked August 2026
#coverage#csf

Now you: objective 8.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

8-1Security Capability Selection, Placement, Configuration

An administrator asks which outcomes the CSF places in the RESPOND Function. Which set does NIST document?

Sample question 2 of 3

8-1Security Capability Selection, Placement, Configuration

An administrator asks what the RECOVER Function supports under the CSF. What does NIST document?

Sample question 3 of 3

8-1Security Capability Selection, Placement, Configuration

An administrator asks what understanding assets and suppliers enables under the CSF IDENTIFY Function. What does NIST document?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Capability Selection, Placement, Configuration