Objective 8.5

Cybersecurity Defense Architect

Define technology implementation strategies to provide desired capabilities

Objective 8.5 sits in Security Capability Selection, Placement, Configuration, which carries 15% of the Cybersecurity Defense Architect exam. The questions below are original, written from the official objective title above, and each explanation cites the Splunk page it rests on.

Objective title verbatim from the official objectives. Splunk exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

8-5Security Capability Selection, Placement, Configuration

An administrator asks what the CSF supplementary resources are documented to help an organisation do. Which set does NIST name?

Detect, contain and recoverThose are incident handling stages.
Certify, audit, attest, publishThe CSF is not a certification or attestation scheme.
Build, test, deploy, monitorThose are software delivery stages.
Understand, assess, communicateCorrect · your answerCorrect.

Correct.

Checked against nvlpubs.nist.gov, August 2026

Concept

An implementation strategy needs a sequence that ends in communication. A plan nobody can explain to a budget holder does not get funded.

Why D

NIST documents that an organization can use the CSF Core, Profiles and Tiers with the supplementary resources to understand, assess, prioritize and communicate cybersecurity risks.

Source

An organization can use the CSF Core, Profiles, and Tiers with the supplementary resources to understand, assess, prioritize, and communicate cybersecurity risks.

NIST CSWP 29: The NIST Cybersecurity Framework (CSF) 2.0, checked August 2026
#implementation#csf

Now you: objective 8.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

8-5Security Capability Selection, Placement, Configuration

An administrator asks what an Organizational Profile Template is documented to help with. Which does NIST name?

Sample question 2 of 2

8-5Security Capability Selection, Placement, Configuration

An administrator asks how NIST characterises the management of cybersecurity risk over time. What does the CSF state?

Full Cybersecurity Defense Architect question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Capability Selection, Placement, Configuration