Security Architecture
405 soru
A fintech platform is designing its microservices-based API infrastructure. The mobile application client must request access to user data across multiple independent backend services on behalf of authenticated users. The architecture requires that microservices independently verify scoped permissions statelessly without querying a central authentication service on every request, while avoiding exposure of user credentials. Which of the following identity and access management architecture designs best satisfies these requirements?
A security architect is designing a high-availability infrastructure for an enterprise core database server connected to a Storage Area Network (SAN) using dual Host Bus Adapters (HBAs) connected across separate SAN fabrics. During failure simulation testing, disconnecting one fiber channel link caused the database operating system to freeze due to input/output timeouts rather than redirecting I/O operations through the secondary healthy storage fabric. Which of the following operating system level capabilities should the architect configure to enable seamless storage path failover and traffic load distribution?
A security engineer is designing a secure storage architecture for an enterprise financial organization migrating sensitive customer records to a public cloud object storage environment. To meet compliance standards and protect data at rest against unauthorized cloud administrator access and physical disk theft, which of the following controls should the engineer implement? (Select TWO).
Geçerli olan tümünü seçin
A security administrator is reviewing the automated failover process for a high-availability cluster to ensure continuous operations during a hardware failure. What is the correct order of steps the cluster system takes when a primary node fails?
Öğeleri doğru sıraya koymak için sürükleyin
A financial enterprise is migrating its identity architecture to a cloud-hosted Identity Provider (IdP) while retaining a mission-critical legacy on-premises web application. The legacy application relies strictly on Integrated Windows Authentication (Kerberos) for user authentication and cannot be modified to support modern web standards such as SAML 2.0 or OpenID Connect (OIDC). Remote employees connect from unmanaged endpoints without direct line-of-sight network connectivity to internal Active Directory Domain Controllers. Which architectural pattern should the security team implement to provide secure single sign-on (SSO) to this application while maintaining a Zero Trust security posture?
An enterprise security architect is categorizing modern enterprise workloads according to cloud service models and deployment architectures. Match each system requirement on the left with its corresponding cloud model on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security architect is evaluating advanced identity and access management (IAM) architectural components to enforce Zero Trust principles and streamline operations across a hybrid enterprise environment. Match each IAM architectural pattern to the specific security or operational requirement it is designed to address.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial technology organization is deploying a multi-tier payment processing service using a managed Platform as a Service (PaaS) database solution provided by a cloud vendor. Under the cloud shared responsibility model, which of the following security tasks remains the exclusive responsibility of the organization's engineering team?
An enterprise organization installs two independent Internet Service Provider (ISP) lines connected to a perimeter router. If the primary connection experiences an outage, network traffic immediately routes through the secondary line to prevent network disruption. Which of the following resilience concepts is best demonstrated in this scenario?
A financial services organization maintains an on-premises datacenter hosting a critical legacy mainframe database and a public cloud environment running web microservices. The organization must allow cloud microservices to query specific API endpoints on the mainframe without exposing the mainframe's on-premises subnet to the entire cloud Virtual Private Cloud (VPC) and without allowing lateral East-West traffic if a cloud service is compromised. Which secure network design approach best achieves this requirement?
A high-precision robotics enterprise is implementing Zero Trust Architecture (ZTA) controls for remote field engineers accessing edge industrial control systems. An engineer successfully authenticates and establishes an active session to deploy firmware. Ten minutes into the session, real-time endpoint telemetry alerts the system that the engineer's workstation has disabled its local host firewall and initiated an unverified concurrent wireless network connection, severely degrading its dynamic security posture score. Which of the following actions should the Policy Decision Point (PDP) execute to maintain Zero Trust tenets?
An enterprise security architect is designing an Identity and Access Management (IAM) framework to integrate a newly acquired subsidiary into the organization's cloud identity infrastructure. The solution must provide cross-domain web-based federated Single Sign-On (SSO) for web applications, automate real-time user identity lifecycle provisioning and deprovisioning between the Identity Provider (IdP) and third-party SaaS platforms, and align strictly with Zero Trust architecture principles. Which of the following architectural standards and protocols should the architect deploy to fulfill these requirements? (Select TWO).
Geçerli olan tümünü seçin
Match each Identity and Access Management (IAM) protocol or standard to its primary architectural function in an enterprise environment.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security administrator is hardening a container runtime environment hosting third-party microservices on a shared host node. To minimize the blast radius of a potential container exploit, the administrator needs to enforce strict privilege boundary controls on container processes. Which TWO of the following security configurations should be implemented to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network security architect is establishing ingress and zone traversal inspection controls for a public-facing e-commerce platform. The architecture requires multi-tiered network segmentation to isolate external web traffic from sensitive internal backend databases. In what order should inbound network traffic pass through these security controls and network zones, starting from initial external ingress to the final destination in the isolated database zone?
Öğeleri doğru sıraya koymak için sürükleyin
An e-commerce enterprise is deploying an automated cloud storage repository for sensitive database backups containing customer personally identifiable information (PII). Regulatory compliance mandates that all bulk data must be encrypted at rest with high throughput, while key lifecycle management must be secured by a dedicated hardware root of trust to prevent key extraction. Which architecture best fulfills both performance and key protection requirements?
An enterprise e-commerce organization is migrating its real-time product recommendation system to a serverless Function-as-a-Service (FaaS) architecture hosted by a public cloud service provider (CSP). Which TWO of the following security tasks remain the direct responsibility of the enterprise organization under the cloud shared responsibility model?
Geçerli olan tümünü seçin
An enterprise security architecture team is redesigning identity federations across several vendor SaaS applications. To align with Zero Trust principles, the organization requires immediate session termination and access token revocation across all connected SaaS applications the moment an identity risk signal (such as impossible travel or device compliance failure) is detected at the central Identity Provider (IdP), rather than waiting for OAuth access tokens or SAML assertions to expire naturally. Which of the following identity architectural mechanisms best fulfills this real-time session security requirement?
A biotechnology company needs to isolate its laboratory network housing unpatchable legacy gene-sequencing equipment. The laboratory devices must push telemetry data and analysis reports outward to a central server in the enterprise corporate zone, but the security architecture must strictly guarantee that no incoming connection requests or lateral traffic can reach the laboratory network from the corporate zone. Which of the following network controls best fulfills these security constraints?
An enterprise organization is designing a disaster recovery strategy for its critical e-commerce platform. To ensure continuous business operations, the organization requires an off-site recovery facility that is fully configured with active servers, network infrastructure, and real-time data synchronization, allowing it to immediately assume operational duties if the primary site fails. Which of the following recovery site types best satisfies these requirements?