Objective 8.4

Cybersecurity Defense Architect

Explain methodologies used to select security technologies aligned to business need, organizational technology landscape, and security controls

Objective 8.4 sits in Security Capability Selection, Placement, Configuration, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

8-4Security Capability Selection, Placement, Configuration

An administrator selects controls for a regulated system. Where does NIST document the baselines that guide selection?

The CSF CoreThe CSF Core lists outcomes rather than controls.
SP 800-53 Revision 5Revision 5 holds the control catalogue itself.
SP 800-53BCorrect · your answerCorrect.
SP 800-61r3SP 800-61r3 covers incident response.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

A catalogue lists what exists; a baseline says what applies. Selection methodology depends on knowing which document answers which question.

Why C

NIST documents that SP 800-53B contains security and privacy control baselines for federal information systems and organizations.

Source

SP 800-53B contains security and privacy control baselines for federal information systems and organizations.

NIST SP 800-53 Revision 5: Security and Privacy Controls, checked August 2026
#selection#controls

Now you: objective 8.4 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

8-4Security Capability Selection, Placement, Configuration

An administrator must fit a standard baseline to an unusual technology estate. Which mechanism does NIST document for that?

Sample question 2 of 2

8-4Security Capability Selection, Placement, Configuration

An architect asks how Enterprise Security dashboards are grouped to match the capabilities an organisation needs. Which grouping does Splunk document?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Capability Selection, Placement, Configuration