Security Architecture
405 questions
An organization is deploying a custom web application to a cloud environment where the cloud service provider manages the underlying hardware, operating system, and web server runtime environment. The organization's development team is responsible only for deploying their application code and managing the application data. Which cloud service model is being utilized in this scenario?
An enterprise organization is migrating its core billing application to a public cloud using an Infrastructure as a Service (IaaS) deployment model. Which of the following security tasks remain the direct responsibility of the enterprise customer within this framework? (Select TWO.)
Select all that apply
A technology firm has deployed several virtual machines on an Infrastructure as a Service (IaaS) public cloud platform. According to the cloud shared responsibility model, which of the following security tasks is the sole responsibility of the customer?
An enterprise security architect is mapping security governance duties across various cloud service models during a multi-cloud initiative. Match each cloud service model on the left with the customer's primary security responsibility on the right.
Click a left item, then click its matching right item
Items
Matches
An e-commerce organization is transitioning its customer portal microservices from self-managed virtual machines running in an Infrastructure as a Service (IaaS) environment to a managed Platform as a Service (PaaS) application hosting engine. Which of the following security management tasks is transferred from the organization to the cloud service provider as a direct result of adopting this PaaS model?
A healthcare provider maintains an on-premises data center for storing confidential patient health records to maintain direct physical oversight. To handle peak computing demands during annual health audits, the provider integrates resources from a public cloud vendor. Which cloud deployment model is the organization utilizing?
A financial institution is deploying a microservice platform using a Function-as-a-Service (FaaS) cloud model to process high-frequency transaction requests. During a security architecture review, the compliance team requires a clear matrix of operational duties between the organization and the cloud service provider (CSP). Which of the following responsibilities is retained solely by the enterprise customer under this deployment model?
An enterprise security architect is establishing a security baseline across diverse cloud deployment and service models. Match each security operational task or control responsibility to the corresponding cloud service or deployment model that correctly allocates primary tenant responsibility.
Click a left item, then click its matching right item
Items
Matches
A network administrator needs to isolate legacy industrial control devices that cannot accept software patches from the primary corporate network to prevent unauthorized lateral movement. Which of the following network design techniques best fulfills this security requirement?
A global manufacturing corporation is deploying a multi-cloud security architecture to support collaborative supply chain partner integration, internal software engineering teams, and cloud governance monitoring. Match each cloud architecture model or security control placement on the left with its corresponding responsibility boundary or functional description on the right.
Click a left item, then click its matching right item
Items
Matches
Match each cloud deployment model to its defining security architecture characteristic.
Click a left item, then click its matching right item
Items
Matches
An organization plans to deploy a database solution in the cloud. The company requires the Cloud Service Provider (CSP) to manage hardware provisioning, operating system installation, and database engine maintenance, while the internal IT team retains control over database tables and user permissions. Which cloud service model should the organization select to meet these requirements?
A security architect is developing a cloud security matrix to clarify operational responsibilities across multi-cloud environments. Match each security operational task to the corresponding cloud service model where the customer is primarily responsible for performing that specific task.
Click a left item, then click its matching right item
Items
Matches
A security architect is updating the enterprise security baseline for several subnets and workload environments. Match each network design requirement to the most appropriate architecture technique or isolation mechanism.
Click a left item, then click its matching right item
Items
Matches
A security architect is designing a multi-tier web application network layout for a corporate enterprise. The design requires that public Internet users can access the front-end web servers, but direct connectivity from the Internet to the backend database servers holding sensitive payment data must be strictly prohibited. Furthermore, administrative access to the database tier must be tightly restricted and audited, with lateral East-West movement between unauthorized server segments blocked. Which of the following network architecture designs best achieves this security objective?
A network security team is establishing security zones and access control mechanisms for an enterprise environment. Match each network segmentation strategy on the left to its primary application scenario on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is updating its cloud-native architecture for a healthcare portal processing Sensitive Personal Health Information (PHI). The security architecture team must enforce strict isolation between individual microservices to prevent lateral movement, continuously authenticate every service-to-service communication path, and inspect East-West traffic without relying solely on perimeter boundary firewalls. Which of the following network architecture strategies best satisfies these requirements?
A enterprise security architecture team is revising its infrastructure segmentation strategy to address specific threat models across varied operational zones. Match each network design architectural technique to the security requirement it fulfills.
Click a left item, then click its matching right item
Items
Matches
An organization is transitioning from a traditional perimeter-based security model to a Zero Trust Architecture (ZTA). Which of the following fundamental principles must the organization implement as part of this new architectural framework? (Select TWO.)
Select all that apply
An enterprise security team is implementing a Platform as a Service (PaaS) managed container environment to host web microservices. Under the shared responsibility model, the Cloud Service Provider (CSP) maintains the underlying hardware, hypervisors, and orchestrator control plane. Which of the following operational tasks remains the primary responsibility of the enterprise security team?