Security Architecture
405 questions
An aerospace engineering organization has implemented Zero Trust Architecture (ZTA) controls for engineers accessing proprietary CAD schematics stored in a hybrid cloud repository. During an active remote session from a corporate laptop, the security monitoring system detects that the local endpoint protection agent was disabled and the asset's dynamic risk score surged. Although the engineer successfully completed multi-factor authentication (MFA) at session initiation, access to the repository is revoked instantly. Which Zero Trust Architecture core principle is directly demonstrated by this access enforcement action?
A system administrator is upgrading a mission-critical server to eliminate single points of failure. The server hardware is equipped with dual hot-swappable power supply units. To ensure continuous operation even if a primary utility feed fails, which of the following configuration controls should the administrator implement?
A senior security architect is auditing an enterprise data center infrastructure to eliminate single points of failure (SPOFs) and ensure compliance with strict uptime service level agreements (SLAs). Match each hardware or operational redundancy mechanism to its corresponding technical implementation objective.
Click a left item, then click its matching right item
Items
Matches
An defense contractor is engineering autonomous marine surveying submersibles deployed in untrusted oceanic regions. The vehicle onboard processing unit must generate device-unique cryptographic keys for encrypting collected telemetry. To resist sophisticated physical tamper attacks—such as silicon chip decapsulation, focused ion beam microprobing, and non-volatile memory readout if a submersible is captured—the keying material must not exist as stored digital bits anywhere on physical media when powered off. Which hardware security technology should be implemented to meet this requirement?
An enterprise automated distribution center utilizes networked Industrial Internet of Things (IIoT) controllers for material handling equipment. The security architecture team must enable the corporate enterprise resource planning (ERP) platform to exchange telemetry and commands with the IIoT controllers while preventing compromised IIoT devices from traversing laterally into corporate endpoints. Which of the following network design controls should the security team implement? (Select TWO.)
Select all that apply
A university is expanding its online video streaming platform by establishing a hybrid cloud architecture. The IT security team deploys virtual machines within a public cloud Infrastructure as a Service (IaaS) tenant to handle high-throughput video transcoding workloads, while maintaining student academic records within an on-premises datacenter. Which of the following operational security responsibilities fall solely on the university's internal security team for the public cloud IaaS components? (Select TWO.)
Select all that apply
A biomedical research enterprise is migrating its hybrid cloud infrastructure to align with Zero Trust Architecture (ZTA) principles to protect sensitive patient records and proprietary research data. Which of the following architectural strategies MUST the security engineering team implement to strictly enforce Zero Trust principles? (Select TWO).
Select all that apply
A system administrator is configuring isolation controls on a host operating system running multiple production application containers. Which of the following security mechanisms directly restrict containerized processes from escalating privileges on the host kernel and limiting system calls? (Select TWO.)
Select all that apply
An organization is updating its high-availability and resilience architecture for a critical enterprise resource planning (ERP) system. A system administrator proposes replacing off-site asynchronous data backups with a local RAID 10 storage configuration, arguing that RAID 10 provides both fault tolerance and complete disaster recovery resilience. Which of the following best explains the fundamental vulnerability created by this proposed change?
A security architect is establishing physical and firmware-level hardening controls for an industrial IoT edge gateway deployed in physically accessible utility substations. Which option correctly matches each embedded hardware security control to its primary operational security role?
Click a left item, then click its matching right item
Items
Matches
Match each storage security technology to its primary operational application within an enterprise architecture.
Click a left item, then click its matching right item
Items
Matches
A global audit firm is implementing a Zero Trust Architecture (ZTA) for partner consultants accessing sensitive financial databases. During an active user session, real-time endpoint telemetry reports that a consultant's laptop has disabled its endpoint detection agent and initiated access from an unrecognized IP address, despite having passed initial Multi-Factor Authentication (MFA). Which of the following architectural responses best exemplifies core Zero Trust principles in this scenario?
An organization wants to enable its employees to access an external web-based software application using their existing internal network credentials without prompting them to re-enter their passwords. Which of the following identity architecture technologies best satisfies this requirement?
An organization is configuring a geographically separated secondary data center to maintain continuous operations for its mission-critical transactional database. The business requirement dictates a Recovery Point Objective (RPO) of zero and automatic failover without human intervention in the event of an site outage. Which of the following technical design choices and infrastructure components must be implemented to fulfill these specific requirements? (Select TWO.)
Select all that apply
A security architect is designing an enterprise deployment strategy incorporating both virtual machines and application containers. Match each architectural isolation mechanism on the left with its corresponding security function or boundary property on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise network security architect is updating the organization's network architecture to enhance isolation and access control. Match each network design or segmentation technique on the left with its corresponding enterprise implementation requirement on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is modernizing its identity and access management (IAM) architecture to support modern web applications and API access controls. Which of the following protocols should the security team implement to provide federated user identity authentication and delegated API authorization? (Select TWO.)
Select all that apply
An energy company is deploying smart grid Remote Terminal Units (RTUs) in unmonitored utility field enclosures. During a physical security assessment, penetration testers attached high-speed logic analyzers to the exposed printed circuit board (PCB) traces connecting the microcontroller to external system RAM, successfully intercepting plaintext cryptographic keys transmitted across the bus during normal runtime operations. Which of the following hardware security controls should the security architect specify to mitigate this vulnerability?
An enterprise financial institution is designing a storage architecture for high-throughput transaction databases hosted on a Storage Area Network (SAN). Security requirements specify that bulk data at rest must be encrypted at the drive hardware level to eliminate host CPU performance degradation, and all storage keys must be centrally managed using a standardized network protocol integrated with a Hardware Security Module (HSM). Which of the following storage security solutions best meets these requirements?
A cybersecurity architect for a critical infrastructure energy provider is aligning enterprise security controls with foundational Zero Trust Architecture (ZTA) principles to protect operational technology (OT) and cloud control systems. Match each Zero Trust principle on the left with its corresponding operational security implementation on the right.
Click a left item, then click its matching right item
Items
Matches