Security Architecture
405 questions
A network security administrator is enhancing default gateway availability for a critical transaction processing subnet. The design mandates that if the active border router suffers a hardware crash, internal client endpoints must maintain outbound connectivity automatically without requiring manual IP reconfiguration or workstation restarts. Which of the following controls best achieves this fault-tolerant requirement?
An organization is deploying a cluster of database servers that require continuous network connectivity at the host level. The infrastructure team must configure host network interfaces to survive an individual cable or switch port failure while simultaneously aggregating bandwidth across two interconnected access switches during normal operations. Which of the following networking mechanisms should the administrator implement to meet these requirements?
A security architect is designing an enterprise Network Access Control (NAC) architecture to secure corporate wired and wireless infrastructure. The design requires mutual authentication between client devices and the network, along with centralized authentication and authorization against the enterprise identity store. Which of the following components or protocols should be integrated to meet these requirements? (Select TWO.)
Select all that apply
An organization is updating its enterprise Identity and Access Management (IAM) architecture to reduce credential exposure and prevent lateral movement across server environments. The security architect needs to eliminate static, long-lived administrator credentials and ensure that elevated privileges are granted only on-demand for specific tasks and automatically revoked upon task completion. Which of the following IAM architectural strategies best fulfills this requirement?
A security administrator is establishing a high-availability disaster recovery plan for a mission-critical web application. During an unrecoverable primary data center outage, administrative staff must execute a site failover to the secondary site. Place the following failover operational steps in the correct chronological sequence from first to last.
Drag items to arrange them in the correct order
An organization is designing an automated identity lifecycle architecture to synchronize user identity state between its cloud-based HR system and its central Identity Provider (IdP). Which of the following requirements must be implemented within this architecture to support secure automated user provisioning and real-time deprovisioning? (Select TWO).
Select all that apply
Match each enterprise identity and access management (IAM) architectural component on the left to its primary functional responsibility on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator is reviewing high-availability cluster resilience and failover mechanisms for mission-critical enterprise services. Match each clustering component or condition on the left with its corresponding operational definition or control mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A security architect is designing an authentication and authorization framework for a newly developed microservices-based web application. The architectural design requires a lightweight, stateless mechanism to securely transport identity claims and delegated authorization scopes between independent API endpoints without maintaining server-side session state or performing repeated directory database lookups for each call. Which of the following IAM standards should the architect implement?
An enterprise organization is deploying a native mobile application that connects to cloud-hosted REST APIs. The mobile client runs in an untrusted environment where embedded client secrets cannot be kept confidential. Which of the following identity and access management architecture components should the security architect implement to securely authorize the mobile application while mitigating authorization code interception attacks?
Match each enterprise identity and access management (IAM) protocol or standard on the left with its primary architectural function on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security architect is designing an Identity and Access Management (IAM) architecture for a hybrid enterprise environment. To align with modern Zero Trust principles, the system must evaluate real-time context—such as user risk score, device compliance state, and access location—before granting access to sensitive cloud databases, rather than trusting users based on network location. Which architectural component in this framework is directly responsible for evaluating these dynamic context attributes against enterprise security policies to render an access decision?
An organization is upgrading its access control infrastructure to allow third-party contractors temporary access to cloud-hosted management portals and APIs. The security team mandates that credentials must not be statically stored on client devices, identity assertions must be centralized via modern web standards, and access decisions must not rely on internal network perimeter position. Which of the following security mechanisms should be incorporated into this Identity and Access Management (IAM) architecture? (Select TWO.)
Select all that apply
A financial enterprise is integrating a legacy on-premises web application—which natively authenticates internal users via Kerberos tickets—with a modern cloud-based Identity Provider (IdP) to support federated single sign-on (SSO) for remote workers. The architecture must enable remote users to authenticate against the cloud IdP while ensuring internal domain controllers and Kerberos Key Distribution Centers (KDCs) are not directly exposed to external network traffic. Which IAM architectural solution best meets these requirements?
A healthcare enterprise is deploying a Zero Trust Architecture (ZTA) across its clinical telemetry systems. During an active diagnostic data transmission session, an endpoint compliance agent reports that a workstation's local security baseline has been modified unexpectedly, though the clinician's multi-factor authentication (MFA) token remains valid and unexpired. Which of the following operations executed by the Zero Trust control plane best demonstrates the principle of continuous verification?
An organization is migrating its customer relationship management operations to a Software as a Service (SaaS) cloud solution. Under the cloud shared responsibility model, which of the following tasks remains the primary responsibility of the organization?
A global logistics organization migrates its freight tracking platform to a cloud provider's managed container orchestration service (PaaS). Under the contract, the cloud service provider maintains the physical host infrastructure, hypervisor layer, and control plane nodes. To maintain regulatory compliance, the organization's security architect must establish the operational control boundaries for the deployment. Which of the following security responsibilities rests exclusively with the organization in this managed cloud model?
An enterprise financial organization is redesigning its network architecture for a cloud-hosted payment gateway platform. While perimeter Next-Generation Firewalls (NGFW) currently inspect all North-South ingress traffic from external clients, recent audit logs revealed that compromised web application nodes in the public presentation subnet attempted unauthorized lateral movement (East-West traffic) to internal database clusters within the same virtual private network. The security team requires a design that enforces granular, application-centric access controls between internal workloads without requiring major subnet re-addressing or causing latency bottlenecks associated with hairpinning internal traffic through a central hardware appliance. Which of the following architectural strategies best satisfies these requirements?
A system administrator needs to configure a mission-critical web server to ensure continuous operation even if a single network interface card (NIC) or power circuit fails. Which of the following hardware resilience controls should the administrator implement to eliminate these specific single points of failure? (Select TWO.)
Select all that apply
A digital media broadcasting corporation stores petabytes of high-definition video archives within an enterprise object storage platform. To fulfill compliance mandates from content licensors, the security team must implement a data protection solution that enforces hardware-rooted key protection, strict audit logging of key access requests, and annual key rotation. Crucially, the key rotation process must not require re-encrypting the underlying multi-terabyte static data objects. Which of the following storage security architectures best meets these combined requirements?