Objective 8.2

Cybersecurity Defense Architect

Determine how coverage gaps can be mitigated by architecture changes, config changes, or process changes

Objective 8.2 sits in Security Capability Selection, Placement, Configuration, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

8-2Security Capability Selection, Placement, Configuration

An administrator finds a detection gap and asks which cause Splunk documents first. Which is named?

Mis-configured data collectionCorrect · your answerCorrect.
Insufficient search capacitySearch capacity affects speed rather than coverage.
Missing dashboard panelsDashboard content does not create a gap.
Unassigned notable ownersOwnership is a workflow attribute.

Correct.

Checked against help.splunk.com, August 2026

Concept

Most gaps close with an onboarding change rather than a new rule. Diagnosing the cause decides whether the fix is configuration or engineering.

Why A

Splunk documents that issues such as mis-configured data collection can lead to detection gaps, so log sources should be reviewed for correct ingestion.

#gaps#remediation

Now you: objective 8.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

8-2Security Capability Selection, Placement, Configuration

An administrator asks which two failure modes Splunk names when verifying detection rules work accurately. Which pair is documented?

Sample question 2 of 3

8-2Security Capability Selection, Placement, Configuration

An architect asks how Detection studio expresses coverage against the threat landscape. Which framework does Splunk name?

Sample question 3 of 3

8-2Security Capability Selection, Placement, Configuration

An administrator asks which Detection studio component identifies the techniques used in a detection. Which does Splunk name?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Capability Selection, Placement, Configuration