Security Architecture
405 questions
An organization experiences an unexpected municipal power grid failure at its primary data center. Although the rack-mounted Uninterruptible Power Supply (UPS) units immediately supplied emergency battery power to critical servers, all systems abruptly shut down 15 minutes later when the batteries depleted. An investigation revealed that the facility's backup diesel generator successfully started, but utility power was never switched over to generator power. Which of the following components should the security architect install to automate switching between primary utility power and secondary generator power?
A security architect is designing hardware-level protections for unattended retail payment kiosks deployed in public environments. To protect payment encryption keys against physical memory extraction and ensure that only authenticated firmware executes during startup, which of the following hardware security controls should be implemented? (Select TWO.)
Select all that apply
A network architect is designing a high-availability edge network infrastructure for a regional operational facility. The architecture must ensure continuous default gateway availability for local internal hosts and dynamic, redundant routing across two independent upstream Internet Service Providers (ISPs). Which of the following resilience mechanisms should the architect deploy to fulfill these requirements? (Select TWO.)
Select all that apply
An enterprise security architecture team is categorizing identity standards and protocols for a multi-cloud infrastructure deployment. Match each Identity and Access Management (IAM) protocol or standard on the left to its corresponding architectural use case on the right.
Click a left item, then click its matching right item
Items
Matches
A software enterprise is redesigning access controls for its third-party developer API integration portal. Currently, after external developers authenticate through a legacy VPN connection, their sessions are implicitly trusted across internal staging systems. The enterprise wants to modernize this architecture to align with Zero Trust Architecture (ZTA) principles. Which of the following strategies best implements Zero Trust for these third-party developer connections?
A healthcare organization is updating its enterprise Identity and Access Management (IAM) architecture to support dynamic, fine-grained access control across decoupled microservices. The security team requires a centralized component that evaluates contextual attributes—such as user role, device posture, time of day, and resource sensitivity—against security policies to issue an authorization decision for each access request. Which architectural component directly performs this policy evaluation to determine whether access should be granted?
A logistics company is deploying telemetry edge devices on freight vehicles. To protect against unauthorized firmware tampering, the systems engineer must guarantee that the microcontroller only executes cryptographically signed boot code during power-on. Which hardware security control serves as the immutable foundation to perform this initial integrity verification?
Match each core Zero Trust Architecture (ZTA) functional component to its primary operational responsibility within an enterprise security infrastructure.
Click a left item, then click its matching right item
Items
Matches
A cloud security architect is evaluating a high-availability strategy for a critical online payment application. The application requires near-zero Recovery Time Objective (RTO) and real-time transaction consistency across two distinct cloud regions. A system administrator proposes using asynchronous database replication paired with automated failover via DNS routing, but without implementing a third-site witness or quorum node. Which of the following risks is MOST likely to occur if a network partition isolates the primary region while servers in both regions remain fully operational?
A systems engineer is hardening enterprise endpoints, embedded controllers, and server infrastructure. Match each hardware security feature on the left with its primary operational function on the right.
Click a left item, then click its matching right item
Items
Matches
A regional healthcare network is redesigning its infrastructure to align with Zero Trust Architecture (ZTA) principles for biomedical IoT equipment, such as infusion pumps and vital sign monitors. Historically, once a biomedical device successfully completed initial 802.1X authentication on an internal switch port, it was granted persistent trust and unmonitored network access to servers containing electronic health records (EHR). Which of the following implementations best fulfills the Zero Trust requirement for resource access control in this scenario?
An organization is updating its enterprise access architecture to grant external partner employees access to web applications hosted in a private cloud. The security team requires a federated identity solution that allows partners to authenticate using their own Identity Provider (IdP) and transmit digitally signed XML security assertions to the relying application without syncing credentials or exposing internal directory endpoints. Which of the following identity standards should the security team implement?
A global telecommunications enterprise is migrating its remote network maintenance infrastructure to align with Zero Trust Architecture (ZTA) principles. Field engineers require frequent administrative access to edge router control planes located across dispersed datacenters. Which of the following architectural requirements must be satisfied to uphold core Zero Trust tenets? (Select TWO.)
Select all that apply
An enterprise data center security team is deploying new high-density rack servers equipped with Baseboard Management Controllers (BMCs). To protect against persistent firmware-level compromise, the security architect must ensure that the BMC initial boot code cannot be altered and that attackers cannot downgrade the firmware to a previously signed version containing known security vulnerabilities. Which of the following hardware security mechanisms should the architect specify to fulfill these requirements?
An organization is redesigning its database architecture to maintain continuous uptime for a critical online transaction system. The system requires continuous availability even if an entire database server experiences a hardware controller or motherboard failure. The infrastructure team suggests installing a hardware RAID 10 array on a single database server, claiming this will meet the high availability requirement without needing additional server nodes. Which of the following best explains why this proposed solution fails to satisfy the requirement?
A software engineering team is developing a backend service that must automatedly transmit sensitive transaction audit logs to an external analytics vendor's endpoint. The security team specifies that the integration must eliminate static, long-lived API keys in application configuration files and support short-lived, cryptographically verifiable tokens for machine-to-machine authentication. Which of the following identity and access management architecture solutions should be implemented to satisfy these requirements?
An enterprise security architect is designing an Identity and Access Management (IAM) framework to address several distinct security requirements across a hybrid cloud environment. Match each IAM architectural mechanism on the left with its corresponding enterprise use case on the right.
Click a left item, then click its matching right item
Items
Matches
A security architect is establishing high availability guidelines for enterprise infrastructure. Which architectural control specification best matches each resilience technology?
Click a left item, then click its matching right item
Items
Matches
An agricultural engineering team is deploying autonomous field-monitoring drones that operate in remote, unmonitored locations. To protect the drone flight control systems against unauthorized firmware modifications and ensure hardware-isolated cryptographic key security, which of the following hardware security controls should the engineers implement? (Select TWO.)
Select all that apply
An enterprise organization is deploying Zero Trust Architecture (ZTA) across its cloud and on-premises infrastructure. Match each core Zero Trust principle on the left with its corresponding operational security mechanism on the right.
Click a left item, then click its matching right item
Items
Matches