Security Architecture
405 questions
A cloud-native financial services company is updating the security architecture of its containerized microservices platform, which handles real-time payment transactions. The security team must limit lateral movement across internal workloads, enforce zero trust principles for internal service communication, and ensure continuous traffic inspection. Which of the following technical controls should the security team implement to achieve this network segmentation design? (Select TWO).
Select all that apply
During a technical security assessment of an enterprise cloud environment, a security engineer discovers that a process running within a containerized workload executed a host kernel exploit to access memory allocated to neighboring containers on the same host. To mitigate this risk, the organization must implement an architecture that prevents shared-kernel vulnerability exploitation by providing an independent kernel and hardware-enforced separation for each workload. Which of the following solutions should the engineer recommend?
An enterprise organization is deploying a centralized storage architecture hosting high-value transactional databases. Compliance regulations require that all storage volumes maintain encryption at rest, and master cryptographic keys must be generated, safeguarded, and offloaded to dedicated hardware isolated from host OS administrators to prevent unauthorized key extraction. Which of the following solutions should the security architect integrate into the storage architecture to fulfill this key management requirement?
A regional financial institution migrates its customer ticketing platform to a public cloud provider under a Software as a Service (SaaS) model. During an architectural security review, the team evaluates operational duties under the cloud shared responsibility model. Which of the following security controls remains the sole responsibility of the financial institution?
A regional health insurance organization is migrating its claims processing engine to a cloud provider using a Serverless Function-as-a-Service (FaaS) execution model connected to a managed Database-as-a-Service (DBaaS) backend. During a compliance audit, the security team is asked to document control ownership across the deployment layers. Which of the following statements correctly identifies the customer's operational responsibility in this deployment architecture?
A security engineer is hardening a shared Linux host operating system that runs multiple microservices inside runtime containers. To prevent a compromised container process from escalating privileges on the host or compromising adjacent workloads sharing the same host kernel, which TWO security mechanisms should the engineer implement? (Select TWO.)
Select all that apply
A retail chain is redesigning its store network architecture to satisfy payment card industry compliance requirements. Each store location operates on-site Point-of-Sale (POS) terminals connected to a shared local switch alongside store manager workstations and guest access points. To minimize audit scope and prevent lateral threat movement if a single terminal is compromised, POS terminals must be blocked from communicating directly with one another on the local switch while retaining full access to the router default gateway for transaction processing. Which network design control should the security engineer implement on the local switch?
A global transport logistics enterprise operates edge processing nodes in regional data centers to handle real-time vehicle telematics. High-frequency microservices exchange East-West traffic with strict low-latency requirements, while aggregate telematics summaries are transmitted North-South to the central corporate cloud. A security assessment revealed that external vendor technicians connect to administrative interfaces using direct subnets, creating significant risk of lateral movement across internal services. Which of the following network architecture designs best secures the edge processing environment while preserving performance and administrative isolation?
A municipal water utility is designing a network architecture to allow its corporate analytics platform to pull daily operational telemetry logs from a Supervisory Control and Data Acquisition (SCADA) server located inside a high-security Operational Technology (OT) zone. The organization's security policy strictly forbids any inbound network connections into the SCADA zone and prohibits direct bi-directional TCP/IP session establishment between the corporate network and the OT environment. Which of the following network architecture controls best fulfills these requirements?
A system administrator needs to protect sensitive data stored on enterprise storage drives against physical theft while ensuring that the underlying cryptographic keys are securely generated and managed using a dedicated hardware appliance. Which of the following technical controls should be implemented to fulfill these requirements? (Select TWO)
Select all that apply
An organization needs to monitor and prevent sensitive data, such as personally identifiable information (PII), from being copied onto unauthorized USB storage devices or uploaded to unauthorized web services by internal users. Which of the following data protection solutions is designed to inspect file contents and enforce access policies based on data classification rules?
A enterprise payment processing organization needs to protect sensitive credit card Primary Account Numbers (PAN) stored within a centralized relational database. The security architecture team must ensure that if an unauthorized user or database administrator queries the storage tables, the sensitive numerical data is not exposed. Additionally, downstream analytics applications must be able to process database records without altering the underlying database schema length or data format. Which of the following storage data protection mechanisms best meets these architectural requirements?
An enterprise network administrator needs to add a dedicated hardware appliance to the data center to handle high-volume cryptographic processing and securely protect master private keys. Which of the following hardware security controls best satisfies this requirement?
An enterprise cloud security architect is establishing baseline control requirements for host operating systems, hypervisors, and container runtime environments across a hybrid infrastructure. Match each security mechanism to its corresponding isolation property or security enforcement role.
Click a left item, then click its matching right item
Items
Matches
A commercial maritime cargo fleet operator is upgrading the network architecture of its oceanic container vessels. Each vessel operates an onboard Integrated Platform Management System (IPMS) that manages engine propulsion, steering control, and ballast sensors. The operations team requires continuous, real-time diagnostic telemetry transmitted from the IPMS to a cloud-based monitoring portal via an onboard satellite communications transceiver. However, strict maritime cybersecurity standards dictate that no inbound communication vectors or return-path network packets may ever reach the critical IPMS control network segment. Which of the following network architecture controls BEST satisfies the operational telemetry requirement while enforcing absolute inbound traffic prevention?
A security analyst is evaluating deployment options for a high-security workload that requires strong, hardware-level isolation from other applications sharing the same physical server. Which of the following deployment technologies provides this hardware-level abstraction by running a separate guest operating system on top of a hypervisor?
An enterprise financial network is deploying a high-throughput NVMe Storage Area Network (SAN) array to process ultra-low latency trading transactions containing sensitive data. The lead security architect must ensure all data at rest is cryptographically protected against physical drive theft or unauthorized removal from the data center without degrading storage controller IOPS performance. Furthermore, drive decommissioning must support instant cryptographic erasure without requiring manual degaussing or physical drive shredding, while root keys must be bound to a centralized enterprise key management architecture over Key Management Interoperability Protocol (KMIP). Which architectural design strategy best satisfies all of these operational and cryptographic requirements?
A software development team is deploying a microservice application using containerization on a shared Linux host operating system. To mitigate the risk of a compromised container issuing malicious system calls directly to the host OS kernel, the security administrator needs to restrict syscall availability for the container runtime environment. Which of the following is the most effective security control to achieve this requirement?
An enterprise organization is designing a high-availability infrastructure for a mission-critical financial application. The business requirements state that the system must maintain a Recovery Point Objective (RPO) of zero and support automated failover across geographically separated data centers. The lead architect proposes an active-passive dual-datacenter configuration utilizing asynchronous storage volume replication and dynamic DNS routing to switch client traffic upon primary site failure. Which of the following evaluations best explains why this proposed design fails to meet the organization's requirements?
A enterprise network security architect is reviewing the organization's network segmentation model across physical, virtual, and industrial environments. Match each network segmentation approach to the business and architectural requirement it best addresses.
Click a left item, then click its matching right item
Items
Matches