Security Architecture
405 questions
An enterprise organization is migrating a mission-critical web service to a public cloud Infrastructure as a Service (IaaS) environment utilizing customer-managed virtual machines behind a cloud provider's network load balancer. Under the cloud Shared Responsibility Model, which of the following security functions remain the explicit responsibility of the enterprise security team? (Select TWO.)
Select all that apply
A biomedical research organization is implementing an event-driven serverless (Function-as-a-Service) workflow to process sensitive genomic datasets. The solution operates within a community cloud model shared among research partners and integrates with an on-premises data repository via a secure hybrid connection. The security architecture team must define strict operational responsibilities in accordance with the cloud shared responsibility model. Which of the following security management tasks remain the direct responsibility of the biomedical research organization? (Select TWO.)
Select all that apply
A healthcare technology enterprise deploys an event-driven application using cloud-managed API gateways, serverless execution functions (FaaS), and a managed NoSQL database service to ingest patient telemetry data. The chief information security officer (CISO) requires a security matrix mapping operational duties under the cloud service provider's shared responsibility model for serverless workloads. Which of the following tasks is exclusively the responsibility of the customer organization?
A network security technician is configuring access controls for a healthcare portal. The technician establishes a system that continuously authenticates user identity, validates device compliance, and evaluates permissions for every resource request, even when traffic originates from within the internal corporate network. Which core principle of Zero Trust Architecture is directly demonstrated by this implementation?
A logistics company migrates its core inventory database to a public cloud Infrastructure as a Service (IaaS) environment using custom virtual machine instances. Under the cloud shared responsibility model, which of the following tasks is the sole operational security responsibility of the customer enterprise?
A security architect is designing the network architecture for a manufacturing facility. The site contains a legacy Industrial Control System (ICS) operating sensitive Programmable Logic Controllers (PLCs), alongside an automated telemetry module that needs to push real-time performance metrics to a cloud analytics provider. Enterprise security policy mandates that external cloud systems and corporate IT networks must be strictly prevented from sending incoming traffic back into the ICS network segment. Which of the following network architecture designs best fulfills these security requirements?
A network security architect is implementing defense-in-depth segmentation to secure access from external users to an isolated internal backend database. Arrange the network transit points and security control boundaries in the correct sequence through which inbound traffic must flow from the untrusted Internet to the database server.
Drag items to arrange them in the correct order
A healthcare organization deploys a microservice backend utilizing a serverless Function-as-a-Service (FaaS) architecture on a public cloud platform to ingest patient telemetry. Under the cloud shared responsibility model, which TWO of the following security tasks remain the responsibility of the organization rather than the cloud service provider?
Select all that apply
A security administrator needs to prevent smart building environmental sensors from communicating directly with internal servers holding confidential employee files on the company network. Which of the following secure network design techniques provides the most effective logical isolation for these sensors?
A network administrator is designing a wireless architecture for a company branch office. The goal is to provide visitors with internet access while preventing them from accessing sensitive internal servers and local network resources. Which of the following controls should the administrator implement to achieve secure network segmentation? (Select TWO.)
Select all that apply
A multinational technology company is migrating its customer analytics workloads to a managed Platform as a Service (PaaS) cloud architecture. Under this service model, the Cloud Service Provider (CSP) manages the physical hardware, hypervisors, database engine software, and underlying operating system runtime environments. The company's security engineering team must establish appropriate security architecture controls for the hosted applications and sensitive data. Under the cloud shared responsibility model, which of the following tasks remains the sole responsibility of the customer organization?
An enterprise financial institution is establishing a multi-tenant Community Cloud deployment model shared exclusively among partner credit unions to host a real-time collaborative fraud detection platform. The platform is constructed using managed Platform as a Service (PaaS) microservices that process customer transactions. The enterprise security architect must define control boundaries according to the cloud shared responsibility model and Zero Trust principles. Which of the following security responsibilities rests exclusively with the participating organization's security team?
An enterprise security architecture team is auditing security responsibility boundaries across diverse cloud deployment models and specialized security integrations. Which operational security responsibility correctly aligns with each cloud architecture or deployment model?
Click a left item, then click its matching right item
Items
Matches
Match each Zero Trust Architecture (ZTA) functional component on the left with its corresponding operational role on the right.
Click a left item, then click its matching right item
Items
Matches
A network security team is establishing a zero-trust transit pipeline for remote systems administrators managing a backend database server located in a restricted internal network zone. Place the traffic flow controls and access verification steps in the correct sequential order, from the initial remote connection request to establishing access on the target server.
Drag items to arrange them in the correct order
A financial enterprise security team mandates that every access request to sensitive payment processing services must be explicitly authenticated, authorized, and encrypted, regardless of whether the request originates from an internal office workstation or a remote home connection. Which core principle of Zero Trust Architecture does this policy directly demonstrate?
A financial organization is incorporating a legacy mainframe transaction processing engine into its modern hybrid data center architecture. The legacy system cannot support modern endpoint detection software or host-based firewalls, but it must securely accept transactions from front-end web servers while strictly preventing unauthorized lateral movement to adjacent enterprise database subnets. Which network architecture decision best isolates the legacy system while managing East-West traffic risks?
A Chief Information Security Officer (CISO) is auditing enterprise cloud services to enforce compliance with the cloud shared responsibility model across diverse architectures. Match each cloud service model implementation on the left to the corresponding primary security responsibility retained by the cloud customer on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security administrator needs to isolate public-facing web servers from the internal corporate network to ensure that external internet traffic cannot directly reach internal database servers. Which network design boundary should the administrator implement to host these public services?
An enterprise security architect is designing a defense-in-depth framework across a multi-cloud environment. Match each cloud security technology on the left with its primary operational function on the right.
Click a left item, then click its matching right item
Items
Matches