Security Architecture
405 questions
An enterprise security architect is redesigning identity infrastructure to align with Zero Trust principles for a hybrid workforce. The organization must support real-time token revocation and risk evaluation for SaaS resources when user posture changes, as well as eliminate persistent administrator credentials on legacy infrastructure by enforcing ephemeral privilege allocation. Which TWO of the following identity and access management architecture components or protocols must be implemented to fulfill these requirements?
Select all that apply
An enterprise deploys several virtual machines in a cloud environment. The organization's internal IT team is responsible for installing operating system security patches, configuring guest firewalls, and managing application software, while the cloud provider manages the underlying physical hardware and hypervisor infrastructure. Which cloud service model is being used?
Match each enterprise security management scenario to the cloud service model that reflects its allocation of customer responsibilities under the Shared Responsibility Model.
Click a left item, then click its matching right item
Items
Matches
Match each cloud service model to the primary component managed by the enterprise customer under the cloud shared responsibility model.
Click a left item, then click its matching right item
Items
Matches
A financial institution maintains its core transactional database within an on-premises data center to strictly observe regulatory data sovereignty mandates. During peak quarterly reporting periods, local compute capacity is insufficient. The security team implements an automated architecture that securely extends non-sensitive processing workloads into a third-party public cloud environment while maintaining dedicated encrypted connectivity back to the private data center. Which cloud deployment model is being utilized in this scenario?
A financial technology firm processes sensitive payment transactions using a serverless architecture (Function-as-a-Service) and utilizes a third-party Software-as-a-Service (SaaS) platform for customer records management. Which of the following security tasks remain the sole responsibility of the enterprise customer across these cloud deployment models? (Select TWO.)
Select all that apply
A financial institution is refactoring a monolithic legacy application into a serverless Function-as-a-Service (FaaS) architecture managed via a public cloud provider's API gateway. The cloud provider maintains the underlying physical infrastructure, host hypervisors, and serverless execution runtimes. During an architecture security review, the lead security engineer must establish control placement and operational duties aligned with the cloud shared responsibility model and Zero Trust principles. Which of the following architectural strategies correctly defines the division of security responsibilities between the organization and the cloud provider?
An organization hosts its web application using a Platform as a Service (PaaS) model from a public cloud service provider. Under the cloud shared responsibility model, which TWO of the following tasks remain the responsibility of the customer?
Select all that apply
A logistics enterprise is migrating its legacy inventory management platform to a cloud-hosted Infrastructure as a Service (IaaS) environment. As part of establishing the operational security baseline, the security team is defining the boundary of duties between the customer organization and the cloud service provider (CSP). Based on the cloud shared responsibility model, which of the following security tasks is the exclusive responsibility of the customer organization?
A security architect is updating the network architecture for a pharmaceutical company's laboratory. The network contains legacy instrument controllers operating on legacy software alongside modern cloud-connected analytics platforms. The legacy controllers must transmit processed test metrics to an internal staging database, but must be prohibited from initiating connections to the internet or directly communicating with general corporate workstations. Which of the following controls should the security architect implement to enforce isolation while accommodating operational needs? (Select TWO.)
Select all that apply
A pharmaceutical research firm integrates an on-premises high-performance compute cluster with a cloud-managed Platform as a Service (PaaS) database pipeline to process sensitive genomic records across a hybrid cloud model. To protect data in transit and control unauthorized access, the security team implements an inline Cloud Access Security Broker (CASB) alongside microsegmentation. When evaluating security responsibility boundaries under this PaaS architecture, which security management task remains exclusively the responsibility of the cloud customer?
A security administrator is drafting baseline policies to align the enterprise network with Zero Trust Architecture (ZTA) principles. Which of the following fundamental tenets should be included in these guidelines? (Select TWO.)
Select all that apply
A security engineer is evaluating an enterprise microservices platform where multiple application containers share the underlying Linux host kernel. The engineer needs to enforce a control that restricts containerized application processes from issuing unauthorized or risky system calls (syscalls) directly to the host kernel. Which of the following mechanisms best satisfies this security requirement?
A network administrator needs to ensure that a critical database server remains operational without data loss or downtime if a single internal storage drive fails. Which of the following technical controls directly provides this internal drive-level fault tolerance?
A security team is evaluating a microservices environment where untrusted code executes inside application containers on a shared host operating system. The development team asserts that Linux control groups (cgroups) and namespaces provide the same level of boundary separation as a hardware-assisted Type-1 hypervisor. Which of the following security risks should the security team highlight as the primary concern with this architecture?
A organization needs to integrate its internal directory service with external cloud services so that employees can authenticate to third-party web portals using their existing corporate credentials. Which XML-based open standard should the identity architect select to enable cross-domain single sign-on (SSO)?
A security analyst is establishing baseline service level objectives for system availability and recovery. Match each resiliency metric on the left with its corresponding definition on the right.
Click a left item, then click its matching right item
Items
Matches
A security architect is updating the network architecture for an organization that hosts public-facing web services, internal corporate workstations, and backend databases containing confidential payment data. Which of the following network segmentation controls and design practices should the architect implement to secure East-West traffic and isolate these environments? (Select TWO.)
Select all that apply
An enterprise organization is updating its hybrid storage security architecture to enhance protection for sensitive databases stored on storage area networks (SAN) and prevent unauthorized exfiltration of proprietary data. The security team requires a solution that provides dedicated hardware-backed key protection for disk volume encryption keys, as well as real-time content inspection of egress traffic to block unauthorized data transfers. Which of the following technical controls should the security architect select to meet these requirements? (Select TWO.)
Select all that apply
An enterprise security architect is designing a hybrid Identity and Access Management (IAM) solution to enable Single Sign-On (SSO) for employees accessing both legacy on-premises systems and cloud-hosted web applications. The legacy systems rely on internal Active Directory Domain Services (AD DS) and Kerberos tickets, whereas the cloud applications require SAML 2.0 security assertions. Which of the following architectural controls and components must be deployed to support this hybrid authentication design? (Select TWO.)
Select all that apply