Security Architecture
405 questions
An enterprise security architect is designing an Identity and Access Management (IAM) architecture to support modern cloud applications, API access, network administration, and automated user lifecycle management. Match each IAM protocol or specification on the left to its corresponding architectural use case on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security analyst is designing an isolation architecture for a multi-tenant physical host. The system will process sensitive financial transactions alongside untrusted third-party code. The security policy mandates that a vulnerability exploited in one workload must not allow memory access or host execution privileges over co-located workload instances on the same server. Which of the following isolation strategies best fulfills this requirement?
An enterprise organization is designing a high-availability infrastructure for its edge network services across two geographically separate data centers. The design requires automatic traffic redirection to the healthy data center if a primary site suffers an outage, while minimizing client browser resolution caching during a failover event. Which of the following mechanisms should the security architect deploy to meet these resilience objectives? (Select TWO.)
Select all that apply
An industrial manufacturing facility needs to secure its operational technology (OT) network housing Programmable Logic Controllers (PLCs) from the corporate IT network. Unauthorized network scanning originating from corporate workstations recently reached the shop floor. The security architect must permit authorized engineering personnel to conduct remote maintenance on PLCs while preventing direct network routing between IT endpoints and OT devices. Which of the following network architecture designs best meets these security requirements?
A security architect is designing a cloud backup and object storage architecture to safeguard critical corporate records against unauthorized data exfiltration and ransomware tampering. The design must guarantee data confidentiality at rest while preventing stored backup snapshots from being modified or deleted even if administrative credentials are compromised. Which TWO of the following technical controls should the architect incorporate into the storage design to satisfy these requirements? (Select TWO).
Select all that apply
A maritime shipping enterprise is formalizing its cloud security architecture strategy across diverse operational environments. Match each security operational requirement on the left with the corresponding cloud model or security architecture component on the right.
Click a left item, then click its matching right item
Items
Matches
A security engineer is establishing hardware hardening controls for smart grid embedded devices deployed in physically accessible remote locations. Which of the following hardware-level controls will protect device integrity and prevent unauthorized boot-level tampering? (Select TWO.)
Select all that apply
An enterprise cloud security architect is evaluating isolation boundaries for a multi-tenant microservices platform. The platform currently runs multiple containerized services sharing a single host Linux kernel. During a risk assessment, the team identifies a risk where a kernel-level privilege escalation or vulnerability exploitation within one container could allow an attacker to escape to the host host OS and compromise adjacent tenant workloads. Which of the following deployment strategies provides the strongest architectural isolation boundary to mitigate host kernel sharing risks?
A enterprise storage architect is designing a secure storage architecture for an off-site media storage facility and cloud synchronization gateway that processes large volumes of sensitive customer transactional data. The solution must ensure bulk encryption of data at rest with minimal CPU overhead, enforce hardware-isolated key protection to prevent key extraction, and prevent unauthorized exfiltration of unencrypted sensitive data across network egress interfaces. Which of the following technological controls should the architect incorporate into the architecture design to meet these requirements? (Select TWO.)
Select all that apply
A game development studio migrates its multiplayer matchmaking microservices to a managed Platform as a Service (PaaS) environment hosted by a public cloud provider. As part of defining the organization's cloud security baseline, the architecture team evaluates operational governance duties. Which of the following security responsibilities remains strictly with the game development studio under this cloud service model?
Match each specialized enterprise network architectural scenario with the network segmentation control or isolation mechanism that best satisfies its security and operational constraints.
Click a left item, then click its matching right item
Items
Matches
A biomedical equipment manufacturer is designing an embedded patient monitoring device intended for hospital environments where physical access to the device cannot be fully restricted. To meet strict regulatory standards, the architecture must guarantee that the initial bootloader execution sequence is validated using one-time programmable, non-volatile hardware fuses burned into the system-on-chip during manufacturing, preventing any subsequent firmware update or physical attacker from altering the initial trust anchor. Which hardware security component best establishes this immutable, non-modifiable foundation for the secure boot process?
A software company hosts a critical customer service portal on a Managed Kubernetes platform (PaaS). The cloud service provider (CSP) maintains the master control plane, hypervisor infrastructure, and worker node operating system updates. During a recent vulnerability scan, security auditors identified critical security flaws in the application runtime dependencies packaged inside the deployment container images. Which of the following actions represents the customer's responsibility under the cloud shared responsibility model to remediate these vulnerabilities?
A medical clinic wants to allow guest patients to access the internet via wireless access points while ensuring their traffic is completely isolated from the internal network housing sensitive Electronic Health Record (EHR) systems. Which of the following network design strategies should the security administrator implement on the existing network infrastructure to achieve this isolation?
An enterprise financial organization is designing a hybrid cloud connectivity model for an analytics workload that dynamically offloads data processing from on-premises servers to a public cloud Platform as a Service (PaaS) environment. Security policy mandates that data in transit must never traverse the public internet, data endpoints must not expose public IP addresses, and customer responsibility must be limited strictly to application logic, data classification, and access policies without host management overhead. Which of the following architecture designs and responsibility allocations best fulfills these requirements?
A security administrator is documenting the secure network transit path for a remote system administrator to access a sensitive internal database server via a bastion host. Arrange the following network zones in order from the initial connection point (least secure/untrusted external) to the final destination (most secure internal target).
Drag items to arrange them in the correct order
An organization needs to prevent customer service representatives from copying sensitive customer database files to unauthorized USB flash drives attached to local workstations. Which data protection control should the security analyst implement to enforce this restriction?
A biotechnology company is deploying a cloud-native genomic analysis pipeline utilizing a Function-as-a-Service (FaaS) model coupled with managed cloud object storage. The lead security architect is formalizing operational boundaries to comply with the cloud shared responsibility model. Which of the following tasks remains exclusively the responsibility of the biotechnology company?
An enterprise security architecture team is evaluating modern Identity and Access Management (IAM) components to enhance security across hybrid environments. Based on enterprise security best practices, how should each IAM standard or architecture component be matched to its primary architectural role?
Click a left item, then click its matching right item
Items
Matches
A security architect is designing an Identity and Access Management (IAM) architecture for a microservices-based application deployed across multiple cloud environments. To align with Zero Trust principles, the architecture must issue short-lived, cryptographically verifiable identities to service workloads and decouple fine-grained authorization enforcement from application code. Which of the following protocols or architectural components should the architect integrate to satisfy these requirements? (Select TWO.)
Select all that apply