Security Architecture
405 questions
An industrial manufacturing company needs to isolate its operational technology (OT) network controlling factory machinery from the corporate IT network. The security policy mandates complete physical separation with no logical network connections, wireless links, or shared switching hardware between the two environments. Which network design technique fulfills this requirement?
An online gaming enterprise is transitioning its matchmaking service to a cloud provider's Function-as-a-Service (FaaS) event-driven architecture integrated with a managed API Gateway. As part of establishing the enterprise cloud security baseline, the lead architect must define operational boundaries under the shared responsibility model. Which of the following tasks remain the sole responsibility of the enterprise customer? (Select TWO.)
Select all that apply
Match each network segmentation concept on the left with its defining implementation characteristics on the right. Which pairings correctly connect each segmentation technique to its primary description?
Click a left item, then click its matching right item
Items
Matches
A healthcare organization is updating its network architecture to secure legacy medical imaging endpoints (DICOM equipment) that cannot accept local security agents or operating system patches. The operational design requires these endpoints to stream telemetry outbound to an off-site analytics platform while allowing internal system administrators to perform maintenance. Which of the following network architecture and segmentation controls should the security team implement to isolate the legacy endpoints while satisfying operational requirements? (Select TWO.)
Select all that apply
A healthcare software provider hosts its primary electronic health record (EHR) database within an on-premises data center while leveraging a public cloud Infrastructure as a Service (IaaS) environment for high-throughput batch analytics. The environments are linked via a dedicated direct network connection. During a security baseline review of the public cloud IaaS infrastructure, the security architect must clarify operational duties under the cloud shared responsibility model. Which of the following security controls remains the sole responsibility of the healthcare software provider within the public cloud IaaS segment?
A educational institution transitions its student portal from an on-premises data center to a public cloud Infrastructure as a Service (IaaS) environment. The portal runs on enterprise Linux virtual machine instances provisioned within the cloud provider's Virtual Private Cloud (VPC). Under the cloud shared responsibility model, which of the following security management tasks remains the sole responsibility of the institution's security team?
A security architect for an electrical power distribution utility is designing network security controls for an operational technology (OT) environment. Remote vendor engineers require targeted maintenance access to programmable logic controllers (PLCs) located within the high-security Control Zone. The solution must ensure that remote connections never terminate directly inside the OT segment, prevent lateral movement between distinct PLC subnets, and log all session activity at the network boundary. Which of the following network architecture designs best fulfills these requirements?
A financial technology company is deploying a novel microservice-based payment gateway using a Cloud Service Provider's (CSP) managed Serverless (Function-as-a-Service) platform and managed API gateway. Under the cloud shared responsibility model, which of the following security tasks are the EXCLUSIVE responsibility of the enterprise customer? (Select TWO.)
Select all that apply
A security engineer is designing the network architecture for a utility company's remote smart grid infrastructure. The environment includes hundreds of field sensor gateways that transmit power usage data back to a centralized analytics server. The engineer must ensure that if an attacker physically tampers with and compromises a field gateway, the attacker cannot move laterally to inspect or access adjacent gateways, nor access administrative systems within the internal enterprise network. Which of the following network segmentation controls best satisfies these security requirements?
An organization is deploying Zero Trust Architecture (ZTA) across its network infrastructure. When an employee attempts to access a sensitive human resources portal, which functional component is responsible for evaluating the user's identity, device posture, and enterprise policies to determine whether access should be granted?
A digital media broadcasting network is migrating its video processing pipeline to a cloud-native architecture using a serverless Function-as-a-Service (FaaS) compute layer paired with object storage for asset ingestion. The security engineering team must establish governance over operational tasks according to the cloud shared responsibility model. Which TWO of the following operational tasks remain the sole security responsibility of the broadcasting network?
Select all that apply
An industrial engineering firm operates a critical water treatment facility utilizing legacy Programmable Logic Controllers (PLCs) within an Operational Technology (OT) control zone. The organization must transmit continuous operational metrics to a cloud-based Enterprise Resource Planning (ERP) analytics platform. The security architecture team must ensure that telemetry data moves out of the OT environment while physically preventing any inbound control signals, command injection, or unauthorized network traffic from reaching the legacy PLCs. Which of the following network segmentation designs best achieves this objective?
An enterprise cloud application utilizes a service mesh architecture to handle communication between internal microservices. To reduce authentication overhead and improve performance, a DevOps engineer proposes issuing a persistent session token after an initial mTLS handshake, allowing subsequent microservice calls to bypass per-request authorization checks. Which of the following statements best explains why this proposed design violates core Zero Trust Architecture principles?
A network security architect is reviewing the network segmentation design for an enterprise financial organization. The enterprise must implement appropriate isolation controls across diverse operational environments to satisfy regulatory compliance and mitigate lateral movement risks. Match each network design or segmentation technique on the left with its corresponding enterprise architectural requirement on the right.
Click a left item, then click its matching right item
Items
Matches
Match each Zero Trust Architecture principle on the left with its corresponding operational description on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security architect is evaluating cloud operational boundaries across various enterprise environments. Match each cloud service or deployment model scenario on the left with the corresponding customer security management responsibility on the right.
Click a left item, then click its matching right item
Items
Matches
A security administrator needs to protect sensitive data stored on company laptops by ensuring that storage drives automatically encrypt all data at rest at the hardware layer without relying on the host operating system. Which of the following technologies best fulfills this requirement?
An enterprise security architect is updating the organization's network architecture to mitigate lateral threat movement, secure legacy components, and control administrative access across enterprise zones. Match each network design or segmentation technique on the left with its corresponding architectural application on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise architecture team is designing a NIST SP 800-207 compliant Zero Trust solution to enforce dynamic control plane and data plane boundaries across hybrid environments. Pair each Zero Trust logical component on the left with its precise operational function on the right.
Click a left item, then click its matching right item
Items
Matches
Match each virtualization or containerization security control on the left with its corresponding primary isolation capability on the right.
Click a left item, then click its matching right item
Items
Matches