Security Architecture
405 soru
An enterprise airport operations authority is redesigning its security architecture across operational technology (OT), cloud management, tenant infrastructure, and administrative networks. Match each network isolation and control mechanism on the left to its corresponding architectural requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A logistics enterprise is migrating its fleet tracking telemetry infrastructure to a Zero Trust Architecture (ZTA). The security team is defining architecture baseline policies for API communication between edge gateway devices and core analytical microservices. Which of the following technical requirements directly align with core Zero Trust Architecture principles? (Select TWO).
Geçerli olan tümünü seçin
An IT administrator needs to ensure that all data written to enterprise storage drives is automatically encrypted at the hardware level without placing an operational processing burden on the host operating system. Which of the following storage security solutions best fulfills this requirement?
An industrial IoT device manufacturer is designing a field-deployed microcontroller unit that operates in physically untrusted locations. Security engineers need to prevent attackers from executing anti-rollback (firmware downgrade) attacks—where an adversary physically unsolders external flash memory and writes a cryptographically valid, but older and vulnerable, firmware image. Which of the following hardware security controls best mitigates this physical firmware downgrade vector?
Match each Identity and Access Management (IAM) protocol to its primary architectural use case.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system administrator is auditing isolation and runtime protection controls across a enterprise infrastructure hosting both virtual machines and containerized microservices. Match each security control on the left with the specific operational threat or attack vector it directly mitigates on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A software development firm hosts its multi-tenant build infrastructure on a high-performance Storage Area Network (SAN). During a security assessment, auditors identified two main storage architecture vulnerabilities: block-level data traffic traversing the storage fabric between compute hypervisors and storage arrays is unencrypted and subject to packet sniffing, and logical unit numbers (LUNs) can potentially be accessed by unauthorized host adapters attached to the same fabric switches. Which set of storage architecture controls most effectively mitigates both identified vulnerabilities?
A security engineer is hardening a shared Linux host operating system that runs containerized financial processing microservices. To minimize the risk of a container escape and kernel compromise, which TWO security mechanisms should the engineer implement to restrict container privileges and limit interaction with the host kernel?
Geçerli olan tümünü seçin
Match each storage security technology to its primary operational function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A fintech enterprise is restructuring its cloud-native microservices architecture to mitigate risks associated with lateral movement after a compromised service credential allowed unauthorized database queries. The security engineering team must align service-to-service communication with core Zero Trust Architecture (ZTA) principles. Which implementation strategy best enforces the Zero Trust principles of explicit verification and dynamic access control for every transaction request?
A system administrator is hardening container instances operating on a shared host. Which TWO of the following mechanisms directly enforce kernel-level isolation and resource boundaries for container processes?
Geçerli olan tümünü seçin
A biopharmaceutical research enterprise is refactoring its data protection and storage security architecture across a hybrid deployment containing high-throughput NVMe Storage Area Network (SAN) arrays and off-site cloud object storage. The design must ensure zero-trust data protection for proprietary genomic data at rest and during transit, enforce cryptographically isolated key management, maintain ultra-low latency bulk encryption, and prevent sensitive data exfiltration from endpoint storage interfaces. Which of the following architectural controls should the security architect select to satisfy these enterprise security objectives? (Select THREE.)
Geçerli olan tümünü seçin
A smart utility metering company is migrating its real-time telemetry processing pipeline to a public cloud environment. The architecture utilizes cloud-hosted virtual machines (IaaS) for running custom protocol ingestion agents and a fully managed database service (PaaS) for long-term data warehousing. Which TWO of the following operational security tasks remain the direct responsibility of the utility company's security team across both service models?
Geçerli olan tümünü seçin
A logistics enterprise hosting financial transaction archives on an enterprise Storage Area Network (SAN) must ensure bulk data at rest remains cryptographically protected if physical drives are stolen or improperly decommissioned. The security architecture team mandates that encryption and decryption operations execute directly on the storage controller hardware without host server performance overhead, while key generation and key lifecycle management must remain strictly isolated inside a dedicated FIPS 140-3 validated key management appliance. Which of the following storage security solutions best meets these requirements?
An enterprise security architect is categorizing control plane and data plane functional duties during a Zero Trust Architecture (ZTA) migration. Match each Zero Trust architecture component on the left with its specific operational responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each enterprise data protection architectural control to its corresponding storage security function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A enterprise cloud services provider is decommissioning a high-density, multi-tenant Storage Area Network (SAN) array containing sensitive tenant data. The SAN storage tier utilizes Self-Encrypting Drives (SEDs) configured to manage media encryption keys via a centralized Key Management Interoperability Protocol (KMIP) cluster. Due to lease agreements, the physical NVMe solid-state drives must remain intact and intact hardware must be returned to the lessor within a strict two-hour window. Which of the following technical procedures provides the most effective and cryptographically sound method to ensure all tenant data is permanently unrecoverable before the drives are removed?
An enterprise digital publishing company is migrating its core subscription portal and web application servers to an Infrastructure as a Service (IaaS) environment hosted by a public cloud provider. Under the cloud shared responsibility model, which of the following security operations remains the sole responsibility of the enterprise security team?
An infrastructure engineer is designing network-level resiliency for a critical telemetry gateway cluster operating within an industrial plant. The business continuity requirement specifies that the server nodes must maintain active network connection redundancy across two physically separate upstream access switches. Crucially, the network management team cannot make any configuration changes or protocol modifications (such as enabling port channels or link aggregation) on the existing switches. Which of the following networking configurations should the engineer implement to satisfy these requirements?
During a security audit following an incident attempt on a containerized microservices environment, an analyst discovers that an attacker successfully gained remote code execution within a running container process. However, when the attacker attempted to modify system clock settings and mount host storage volumes, the operations failed because administrative privilege flags were restricted at the kernel level by the container runtime engine. Which security mechanism directly prevented the container process from performing these high-privilege host kernel operations?