Security Architecture
405 questions
An enterprise security architect is refining the organization's data protection and storage security architecture. Match each enterprise storage security objective on the left with the primary storage control or mechanism on the right that best satisfies the requirement.
Click a left item, then click its matching right item
Items
Matches
An organization is migrating sensitive financial API workloads from traditional virtual machines to an unmanaged container orchestration cluster hosted on bare-metal servers. During a security architecture review, the security team expresses concern that a container compromise could lead to host kernel exploitation or unauthorized lateral movement between isolated tenant containers. Which TWO of the following technical controls directly mitigate these runtime isolation risks at the host level?
Select all that apply
A manufacturer of medical IoT devices wants to permanently disable hardware debug interfaces, such as JTAG, prior to shipping devices to customers. This control must be executed at the silicon level so that hardware debugging cannot be re-enabled through software or firmware modifications. Which of the following hardware security mechanisms should the manufacturer use?
A security administrator must securely access an internal database server located within a restricted database zone from a remote management workstation. Place the following connection and transit steps in the correct sequential order from initial external access to final database session establishment according to secure network design principles.
Drag items to arrange them in the correct order
A cloud security architect is establishing isolation and resource protection mechanisms for a hybrid deployment containing both virtualized workloads and containerized microservices. Match each security mechanism to its primary isolation function.
Click a left item, then click its matching right item
Items
Matches
Match each advanced hardware security mechanism or embedded architecture component to its primary operational security function.
Click a left item, then click its matching right item
Items
Matches
A commercial logistics enterprise is migrating its legacy cargo tracking application to an Infrastructure as a Service (IaaS) environment hosted by a public cloud service provider. During the architecture review, the chief information security officer (CISO) requests clarification on operational security boundaries under the shared responsibility model. Which of the following best describes the security responsibility allocation for this deployment?
A healthcare enterprise is architecting a storage and data security solution for its electronic health record (EHR) database environment. The design must ensure bulk data at rest remains cryptographically secured without causing significant performance overhead on database queries, while also preventing unauthorized exfiltration of sensitive patient records across endpoint storage interfaces and removable media. Which of the following security controls should the architect integrate to satisfy these requirements? (Select TWO.)
Select all that apply
A healthcare organization is refactoring its data architecture to secure sensitive patient diagnostic records stored on a Network Attached Storage (NAS) array. The security requirements dictate that data must be encrypted at rest, key lifecycle operations must be centrally managed and audited, and storage administrators must not have direct access to root cryptographic keys or store them on the local NAS hardware. Which of the following data protection solutions best fulfills these architectural requirements?
A global healthcare organization requires a federated access solution allowing external medical specialists from partner hospitals to query patient diagnostic APIs hosted in its cloud environment. The architecture must ensure partner organizations maintain control over their own user credentials, support identity assertion, enable fine-grained attribute-based access decisions at the API gateway without exposing internal directory services, and avoid establishing persistent network-level perimeter trust. Which architectural combination of identity and authorization frameworks best satisfies these security requirements?
A financial enterprise is deploying a third-party reporting server into a virtualized datacenter. The reporting server requires outbound internet access to fetch external market data, but corporate security policy dictates that it must be strictly prevented from initiating lateral connections to any other internal virtual machines, even those within the same subnet. Which of the following network architecture design solutions best satisfies this requirement?
A storage administrator is configuring security mechanisms for sensitive database volumes hosted on an enterprise Storage Area Network (SAN). The administrator needs to protect data at rest with hardware-accelerated bulk encryption and ensure that top-level encryption keys are managed in a tamper-resistant environment. Which of the following technologies should the administrator deploy? (Select TWO.)
Select all that apply
A financial enterprise is decommissioning a multi-tenant cloud storage array containing sensitive personally identifiable information (PII) stored across encrypted block volumes. The architecture relies on envelope encryption where unique Data Encryption Keys (DEKs) are wrapped by Key Encryption Keys (KEKs) managed inside a Key Management Interoperability Protocol (KMIP)-compliant Hardware Security Module (HSM). The compliance team mandates immediate, verifiable data sanitization before the physical storage media is recycled by the provider, but traditional multi-pass disk overwriting would exceed bandwidth limits and disrupt SAN performance. Which of the following storage security architectural approaches best satisfies these operational and compliance constraints?
A security administrator is documenting high-availability and business continuity metrics for an organization's core infrastructure. Match each availability metric on the left with its corresponding description on the right.
Click a left item, then click its matching right item
Items
Matches
A biomedical engineering department at a regional hospital plans to integrate networked smart infusion pumps into the facility's network. To minimize the threat of malware spreading laterally from compromised medical devices to critical electronic health record (EHR) databases while still allowing automated telemetry collection by central servers, which network architecture control should the security team implement?
A enterprise security architect is configuring an automated cross-region database failover workflow between two active-passive data centers to maintain zero Recovery Point Objective (RPO) and minimal Recovery Time Objective (RTO) during an ungraceful outage. Arrange the operational steps of the automated failover sequence in the correct chronological order from first step executed to final step completed.
Drag items to arrange them in the correct order
An enterprise organization operates two data centers connected via a low-latency dark fiber link. The business continuity requirement mandates a strict Recovery Point Objective of zero () for transactional database records during a primary site outage, while simultaneously preventing split-brain conditions during automated failover. Which of the following high-availability storage configurations best satisfies these requirements?
An aerospace security architecture team is designing a satellite communications (SATCOM) avionics gateway for autonomous aircraft. The gateway will operate in environments susceptible to physical interception, probe attacks, and firmware tampering. To meet stringent safety standards, the hardware must establish an immutable boot verification chain and prevent physical extraction of secret keys stored in memory. Which TWO of the following hardware security controls should the team implement to satisfy these architecture requirements? (Select TWO)
Select all that apply
An enterprise security team is upgrading its data protection and storage security architecture to protect sensitive databases and block storage volumes across on-premises SAN and cloud environments. The architect needs to implement controls that ensure centralized key governance for encrypted storage, isolate storage network traffic to authorized hosts, and prevent unauthorized exfiltration of sensitive files from endpoints. Which of the following technical controls should the architect implement to meet these storage security requirements? (Select THREE)
Select all that apply
An enterprise security architecture team is evaluating cloud deployment and service models for a multi-cloud initiative. Match each operational requirement on the left with the most appropriate cloud architecture or service model on the right.
Click a left item, then click its matching right item
Items
Matches