Security Architecture
405 questions
A logistics enterprise is integrating automated freight crane telemetry sensors with its centralized monitoring dashboard. The crane control systems run legacy industrial software that cannot be patched, whereas the monitoring dashboard resides on the corporate administrative network. Which network design control best mitigates the risk of lateral threat movement from the corporate network to the crane controllers while continuing to permit automated telemetry collection?
A security team is implementing an access control model that evaluates contextual variables—such as user location, device security compliance, time of request, and resource sensitivity—before granting access. Which access control architecture model natively uses these dynamic characteristics to make authorization decisions?
An organization is deploying a multi-tenant cloud platform where microservices processing sensitive financial records will run alongside third-party analytics services on the same physical host node. The software engineering team proposes relying solely on standard Linux container runtime features, claiming that container namespaces provide security boundary isolation identical to dedicated virtual machines on a Type-1 hypervisor. Which of the following statements best describes the primary security risk associated with this deployment architecture?
Match each storage security technology on the left with its primary enterprise implementation role on the right.
Click a left item, then click its matching right item
Items
Matches
A healthcare organization is deploying a patient engagement application using virtual machine instances hosted on an Infrastructure as a Service (IaaS) cloud platform. The security architect is defining the operational security responsibilities between the organization and the cloud service provider (CSP). According to the cloud shared responsibility model, which of the following tasks is the sole responsibility of the customer?
A systems administrator is configuring a critical database server to eliminate single points of failure at both the power source and internal storage levels. Which of the following hardware and physical redundancy solutions directly satisfy these resilience requirements? (Select TWO.)
Select all that apply
An organization is updating its enterprise security architecture to streamline user access across external cloud applications. The security team needs to implement standards that support federated single sign-on (SSO) and automated account lifecycle management between the corporate identity provider and SaaS platforms. Which TWO of the following open standards should the team integrate into the IAM architecture to fulfill these specific requirements?
Select all that apply
A security architect is establishing high availability and resilience specifications for a mission-critical infrastructure deployment. Match each resiliency requirement or architectural challenge on the left with its corresponding technical mechanism or metric on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security architect is evaluating modern Identity and Access Management (IAM) controls to enforce Zero Trust principles and streamline federated access across a multi-cloud enterprise. Match each identity architecture protocol or mechanism on the left to its corresponding architectural implementation on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security architect is designing a modern Identity and Access Management (IAM) architecture to support a hybrid enterprise workforce. The solution must provide phishing-resistant, passwordless authentication for corporate users accessing cloud services, while automatically synchronizing user onboarding, role updates, and offboarding privileges from the central Identity Provider (IdP) to external Software as a Service (SaaS) platforms in near real-time. Which of the following protocols or standards should the architect integrate into the IAM architecture to fulfill these requirements? (Select TWO.)
Select all that apply
A security engineer is establishing defense-in-depth security controls for an enterprise cloud platform hosting both application containers and virtual machines. Match each security control mechanism to its primary protective function.
Click a left item, then click its matching right item
Items
Matches
A security engineer is configuring a high-availability perimeter firewall pair using Virtual Router Redundancy Protocol (VRRP) to eliminate single points of failure at the default gateway. During failover testing, when the primary firewall is forcibly rebooted, downstream clients experience dropped sessions and must re-authenticate and re-establish all TCP connections, even though the standby appliance immediately claims the virtual IP address. Which mechanism must be implemented alongside virtual IP redundancy to preserve established network sessions during an unexpected failover?
An IT administrator is deploying a centralized log server that must remain operational without downtime if an individual hard drive suffers a physical failure. Which of the following technologies should the administrator implement to provide this real-time storage fault tolerance?
An enterprise aerospace contractor is modernizing its IT infrastructure across diverse cloud environments. Match each enterprise workload scenario on the left with the corresponding cloud service or deployment model on the right that best represents its architecture.
Click a left item, then click its matching right item
Items
Matches
A security administration team needs to centralize management for administrative console logins across enterprise network routers and switches. The architectural requirements specify that authentication must be decoupled from authorization to enforce granular per-command permissions, and the entire transmission packet body must be encrypted. Which protocol should the team implement?
An organization is modernizing its deployment architecture by hosting multiple containerized microservices on a shared host operating system. During a technical audit, a security analyst discovers that microservices run with standard system privileges, exposing the host operating system kernel to potential privilege escalation via unauthorized system calls if a container is compromised. Which of the following controls should the security team implement on the container host to restrict the specific system calls available to container processes?
A security architect is designing an identity and access management (IAM) infrastructure for an enterprise microservices environment. The organization requires that OAuth 2.0 access tokens issued to client applications are sender-constrained, ensuring that if a token is intercepted in transit, it cannot be replayed by an unauthorized third party to access downstream APIs. Which of the following architectural solutions best satisfies this security requirement?
A cloud security architect is designing a resilient infrastructure for a critical financial transaction service deployed across two geographically distant cloud regions. To satisfy business requirements, the architecture must achieve a Recovery Point Objective (RPO) of zero (zero data loss) and a Recovery Time Objective (RTO) of near-zero in the event of an entire regional failure. Which TWO of the following architectural mechanisms must be deployed together to meet these strict availability and resilience targets?
Select all that apply
A maritime shipping container logistics terminal is modernizing its operational technology (OT) network and port management systems. The security architecture team is adopting Zero Trust Architecture (ZTA) principles to prevent unauthorized access between automated gantry crane control systems, IoT tracking sensors, and cloud management consoles. Which of the following architectural requirements represent core tenets of Zero Trust Architecture that must be implemented in this design? (Select TWO.)
Select all that apply
A pharmaceutical research organization is updating its storage architecture to host confidential genomic sequencing datasets. The security architect must satisfy two primary requirements: guarantee bulk data encryption at rest on storage area network (SAN) arrays without degrading host processing performance, and prevent research data from being copied to unauthorized physical media or unapproved endpoints. Which of the following technical security solutions should the architect select to meet these requirements? (Select TWO)
Select all that apply