Security Architecture
405 soru
An organization is updating its network architecture to securely integrate legacy point-of-sale (POS) terminals with a cloud-based inventory system while maintaining PCI DSS compliance. The legacy POS terminals run older operating systems that cannot support endpoint agent installations or host firewalls. Which of the following network segmentation controls should the security team implement to isolate these legacy devices and restrict unnecessary lateral traffic? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise infrastructure team is redesigning the storage connectivity for a mission-critical database host attached to a Storage Area Network (SAN). The primary goal is to eliminate single points of failure in the physical and logical communication paths between the host server and the storage array, ensuring continuous throughput even if a cable or adapter fails. Which of the following technical controls should the team implement to meet these criteria? (Select TWO).
Geçerli olan tümünü seçin
A municipal transit authority is modernizing its distributed traffic management system and fleet maintenance stations to align with Zero Trust Architecture (ZTA) principles. Which of the following architectural decisions directly fulfill core Zero Trust tenets? (Select TWO.)
Geçerli olan tümünü seçin
A financial services organization is designing a high-throughput database storage system that requires transparent, hardware-level data encryption at rest without burdening the host database server CPUs. Additionally, organizational compliance mandates that encryption keys must be generated and lifecycle-managed by a centralized external key appliance. Which of the following storage security solutions best fulfills these requirements?
A security administrator is reviewing hardware resilience controls for an enterprise web application server host. The server host currently features dual redundant power supplies, hot-swappable cooling fans, and a RAID 10 storage array to prevent single points of hardware failure. However, a recent risk assessment highlighted that if the single physical host chassis or motherboard experiences a hardware fault, the application will become unavailable. Which of the following high-availability solutions should the administrator implement to automatically fail over virtualized workloads to a healthy physical host upon host hardware failure?
A biomedical research firm is implementing Zero Trust Architecture (ZTA) principles to secure sensitive genomic research data stored in a hybrid environment. An analyst attempts to access a restricted database from a corporate laptop while connected from a remote partner facility. Which of the following describes how access is evaluated under Zero Trust principles?
A security architect at a pharmaceutical enterprise is designing the network architecture for a new automated production facility. Match each network design or segmentation technique on the left to its corresponding security application requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each storage security technology on the left with its corresponding enterprise functional mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial services company recently migrated its online portal to a cloud-based containerized microservices architecture. Security telemetry indicates that an attacker successfully compromised a public-facing API gateway container and attempted lateral movement to internal microservices residing on the same Virtual Private Cloud (VPC) subnet. The security team must prevent unauthorized lateral (East-West) communication between workloads within the same subnet without changing the existing IP addressing scheme. Which of the following secure network design controls should the security architect implement?
A security administrator is establishing an automated failover sequence for an active-passive high-availability firewall pair to ensure continuous uptime during a node failure while preserving connection state tables. Place the operational failover steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An autonomous electric vehicle (EV) charging network operator is updating its management plane and edge gateway infrastructure to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Match each Zero Trust logical component to its core operational responsibility within the enterprise architecture.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A storage administrator at a financial enterprise is tasked with securing sensitive transaction logs stored on a high-throughput Storage Area Network (SAN). The solution must protect data at rest against physical drive theft from the data center without introducing computational overhead on the host servers or latency into bulk disk operations. Which of the following storage security controls best satisfies these requirements?
An enterprise infrastructure team is deploying an online transaction application that requires continuous availability and dynamic distribution of user traffic across multiple web servers. The application relies on in-memory user sessions that must remain mapped to the same backend host throughout an active session. If an application node becomes unresponsive, incoming connections must automatically be rerouted to healthy nodes without manual intervention. Which of the following high-availability solutions should the architect implement to meet these requirements?
An organization is designing an updated Identity and Access Management (IAM) architecture for its enterprise applications. The security team needs to support automated user account lifecycle management (creation, updates, and deprovisioning) across multiple third-party SaaS platforms. Additionally, they must implement a fine-grained access control mechanism capable of making real-time authorization decisions based on dynamic contextual attributes such as user location, device security posture, and time of access. Which of the following technologies should the security architect incorporate into the IAM architecture to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A regional energy provider is transitioning its remote field maintenance operations to a Zero Trust Architecture (ZTA). Previously, field technicians authenticated once via Multi-Factor Authentication (MFA) to establish a Virtual Private Network (VPN) session, granting them unrestricted access to internal grid management servers for their entire shift. To align with core Zero Trust principles and eliminate implicit trust, which of the following architectural changes should the security team implement?
A security architect is configuring a zero-trust network ingress path for an administrator connecting remotely to a sensitive database in an isolated zone. Arrange the operational steps for establishing this administrative session in the correct chronological sequence, from initial external initiation to final host authorization.
Öğeleri doğru sıraya koymak için sürükleyin
A security architect is designing an authentication framework for a native mobile application that authenticates users against an enterprise Identity Provider using OpenID Connect. Because native applications are public clients that cannot securely store a static client secret, the architect must mitigate the risk of authorization code interception attacks on the device operating system. Which mechanism should be integrated into the authorization code flow to address this vulnerability?
A security architect is evaluating resilience specifications for an enterprise infrastructure redesign. Match each business availability metric on the left with its corresponding definition on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A university network engineering team is designing an architecture to secure a high-containment biomedical research laboratory. The lab contains unpatchable legacy telemetry devices that must transmit real-time experimental data to an on-premises database in the core enterprise data center, but must be prohibited from initiating or receiving any other traffic across the campus network or the internet. Which of the following network design configurations best achieves this isolation while mitigating lateral movement risks?
A multinational financial services enterprise is transitioning its legacy core banking infrastructure to align with Zero Trust Architecture (ZTA) principles to prevent lateral movement following network breaches. Which of the following architectural strategies MUST be implemented to adhere to Zero Trust principles? (Select TWO.)
Geçerli olan tümünü seçin