Objective 8.3
Cybersecurity Defense ArchitectAffect organizational and company priorities and budgets based on key capabilities required for security that are aligned to security and business goals
Objective 8.3 sits in Security Capability Selection, Placement, Configuration, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.
Objective title verbatim from the official objectives. Splunk exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An administrator must argue for budget using security data. Which NIST measure type quantifies cost savings produced by the programme?
Correct.
Checked against nvlpubs.nist.gov, August 2026Concept
A budget conversation runs on money. Impact measures are the only type NIST defines in those terms, which is why they are the ones to bring.
Why B
NIST documents impact measures as quantifying cost savings produced by the information security program and costs incurred from addressing security events.
Source
NIST SP 800-55 Volume 1: Measurement Guide for Information Security, checked August 2026Impact measures articulate the impact of information security on an organization's unique mission, goals, and objectives by quantifying the following: • Cost savings produced by the information security program • Costs incurred from addressing information security events
Now you: objective 8.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 2
An administrator wants a single figure expressing security investment relative to the organisation. Which example does NIST give?
Sample question 2 of 2
An administrator asks what key indicators are documented to provide on Enterprise Security dashboards. What does Splunk state?
Full Cybersecurity Defense Architect question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Capability Selection, Placement, Configuration
- 8.1 Identify organizational coverage for prevention, detection, response and recovery capabilities
- 8.2 Determine how coverage gaps can be mitigated by architecture changes, config changes, or process changes
- 8.4 Explain methodologies used to select security technologies aligned to business need, organizational technology landscape, and security controls
- 8.5 Define technology implementation strategies to provide desired capabilities
- 8.6 Ensure that resilient solutions aligned to the business and operational requirements are selected and deployed. -