Security Architecture
405 questions
A network administrator needs to host a publicly accessible web server while protecting internal enterprise databases from direct internet exposure. Which network design topology should the administrator implement to place the web server in an isolated perimeter zone between the external internet and the internal private network?
An enterprise security architect is designing a network architecture for a hybrid micro-datacenter that hosts PCI-DSS scoped payment processing workloads alongside unmanaged IoT environmental sensors on shared physical network switches. The design must prevent direct Layer 2 or Layer 3 lateral movement between any endpoints located within the same IP subnet, without requiring dedicated physical switches or administrative overhead from managing hundreds of individual VLAN subnets and IP pools. Which of the following secure network design strategies best meets these requirements?
A regional utility provider migrates its customer telemetry analytics application to a cloud provider's Platform as a Service (PaaS) solution. During a routine vulnerability scan, an auditor discovers an unpatched kernel vulnerability in the underlying host operating system powering the database runtime. Under the cloud shared responsibility model, which of the following parties is responsible for patching this host operating system vulnerability?
A security engineer is designing network controls for a cloud-hosted e-commerce application processing payment transactions. The architecture requires granular security controls to prevent lateral movement (east-west traffic) between individual cloud workload instances within the cardholder data environment. Which network design strategy best provides granular isolation and controls east-west traffic between individual cloud workloads?
A financial services organization operates a microservices-based payment engine within a container orchestration cluster. Public API proxies, payment verification services, and sensitive database connectors execute across shared worker nodes. To mitigate lateral movement risks between workloads running on identical physical hosts while satisfying strict audit compliance, which of the following network architecture controls should the security team implement?
A network administrator needs to establish a remote management session to perform critical database maintenance from an untrusted external network. Arrange the following network boundary transit steps and control points in the correct order, starting from the external connection initiation to the final session establishment on the internal database server.
Drag items to arrange them in the correct order
An organization is updating its enterprise security strategy to align with Zero Trust Architecture (ZTA) principles. Which of the following implementations best demonstrates the core Zero Trust tenet of "assume breach"?
A system administrator is updating an enterprise security policy to align with core Zero Trust Architecture (ZTA) principles. Which of the following practices represent core tenets of Zero Trust? (Select TWO.)
Select all that apply
During a post-incident investigation of a cloud-native microservices environment, a security analyst determines that an attacker exploited a kernel vulnerability within an application container to break out of the container runtime environment and execute code directly on the host operating system. The application was running as a standard non-root service within an OCI-compliant container ecosystem. Which of the following root causes best explains why containerization failed to isolate the workload compared to a traditional hardware-enforced virtual machine architecture?
A network security administrator is setting up access rules for an enterprise environment to ensure strict isolation between public web servers and internal databases, while also maintaining secure remote administrative access. Which TWO network architecture and segmentation practices should the administrator implement to meet these requirements?
Select all that apply
A security analyst is reviewing the security architecture for a hybrid cloud deployment containing both virtual machines and containerized applications. Match each security mechanism on the left with its primary isolation property on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is transitioning several legacy applications to a containerized deployment. A security administrator is explaining to the development team why container security boundaries differ from traditional virtual machine (VM) security boundaries. Which of the following statements accurately describes a fundamental isolation difference between containers and VMs?
A global retail organization is transitioning its legacy transaction processing platform to a hybrid cloud deployment model. The architecture uses Infrastructure as a Service (IaaS) to host legacy relational database instances and Platform as a Service (PaaS) to host modern containerized web frontends. During a cloud architecture security review, the lead security engineer must define operational boundaries under the Shared Responsibility Model for both service types. Which of the following security management tasks remain the exclusive responsibility of the organization across BOTH the IaaS database instances and PaaS web frontends? (Select TWO.)
Select all that apply
An enterprise financial organization is redesigning its Storage Area Network (SAN) security architecture to comply with data-at-rest encryption requirements for bulk database backups. The design must eliminate host server CPU overhead during cryptographic operations and safeguard encryption keys against physical tampering or theft from the data center. Which of the following storage security solutions best meets these requirements?
A DevOps team is deploying microservices within a containerized environment on Linux host servers. The system administrator needs to enforce hard limits on CPU usage and memory consumption for individual containers to prevent a single compromised or misconfigured container from exhausting shared host system resources. Which Linux kernel mechanism should be configured to directly enforce these resource limits?
An enterprise security architect is refining the workload protection matrix for a multi-tenant cloud environment hosting both legacy virtualized infrastructure and microservice containers. Match each virtualization or containerization security control on the left to its corresponding isolation property or policy enforcement mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A fleet logistics company transitions its core routing engine to an Infrastructure as a Service (IaaS) environment provided by a public cloud vendor. The IT team deploys multiple virtual machines to host the application software. Which of the following operational security responsibilities remains exclusively with the logistics company?
Match each storage security mechanism or state to its corresponding enterprise data protection objective.
Click a left item, then click its matching right item
Items
Matches
A security architect is reviewing the access control path for remote administrators connecting from an untrusted management subnet to a high-security internal database zone holding regulated financial records. To enforce defense-in-depth and zero-trust principles, traffic must traverse multiple inspection boundaries and transit controls in a precise order. Sequence the security controls and transit points in the correct order that administrative network traffic must navigate from the originating management workstation to the target database server.
Drag items to arrange them in the correct order
An enterprise facility contains legacy operational technology (OT) devices that cannot receive security updates or support modern encryption protocols. Which network design approach provides the most complete protection by physically isolating these critical devices from all untrusted and corporate network traffic?