Security Architecture
405 soru
An enterprise administrator configures a server with a RAID 5 disk array to ensure continuous availability in the event of a storage drive failure. Following a ransomware incident that encrypted all files on the volume, the administrator replaces one of the physical hard drives with a new spare disk, expecting the rebuild process to recover the original unencrypted files. Which of the following best explains why this recovery strategy failed?
A medical device company is designing a connected infusion pump deployed in hospital environments. To protect against malicious firmware modifications and unauthorized code execution during startup, the device must verify the signature of the boot loader using a cryptographic key burned into immutable hardware during manufacturing. Which hardware-based security control establishes this initial unalterable anchor for cryptographic boot chain verification?
A system architect is designing high-availability storage connectivity for a mission-critical database server connected to a Storage Area Network (SAN). The design must ensure continuous data access even if a host bus adapter (HBA), interconnect cable, or SAN switch fails, while also balancing traffic across active pathways. Which of the following architectural controls should the security architect implement to fulfill this requirement?
A security engineer is designing an embedded industrial sensor node deployed in untrusted physical locations. The design requires that the system only executes cryptographically signed boot code during power-on to prevent unauthorized firmware modifications. Which of the following hardware security controls should the engineer implement to fulfill this requirement?
A financial technology organization is refactoring its internal microservices communication architecture to align with Zero Trust Architecture (ZTA) principles. An application security architect specifies that internal services must no longer trust incoming network traffic based on IP subnets or internal network placement. Instead, every request must be dynamically evaluated against contextual security policies and session health attributes before access is granted. Which logical component within the Zero Trust framework is directly responsible for evaluating these access policies and rendering the authorization decision?
A financial enterprise is deploying specialized infrastructure across regional offices to process centralized database transaction encryption. The security team requires a dedicated hardware-based solution capable of performing high-throughput cryptographic operations while securely storing master keys. The device must ensure keys cannot be extracted even if an adversary gains root access to the host operating system or opens the chassis physical casing. Which of the following hardware security controls best meets these requirements?
Match each enterprise identity and access management (IAM) protocol to its corresponding architectural use case and operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise logistics organization is re-architecting its cloud-native platform to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Which of the following architectural practices must be implemented to establish core Zero Trust controls across the environment? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security team is implementing a Zero Trust Identity and Access Management (IAM) architecture. The team needs to ensure that access to cloud resources is dynamically granted or restricted based on real-time signals, such as user risk level, device health state, and geographic location, rather than relying solely on static group memberships or initial password verification. Which of the following IAM architectural mechanisms should the team implement to satisfy this requirement?
An enterprise security architect is transitioning legacy perimeter security controls to align with Zero Trust Architecture (ZTA) design tenets. Match each Zero Trust architectural concept on the left to its corresponding operational function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A renewable energy utility operates remote maintenance workstations connected to solar farm Supervisory Control and Data Acquisition (SCADA) controllers. Under the existing access model, once a field technician completes initial multi-factor authentication (MFA) at the start of their shift, the active network connection is granted persistent trust across all internal SCADA subnets. The organization wants to refactor this workflow to align with core Zero Trust Architecture principles. Which of the following implementation strategies best satisfies this requirement?
A security administrator is evaluating a high-availability perimeter firewall pair deployed in an active-passive failover configuration. During a scheduled failover simulation, the secondary appliance successfully assumed the virtual IP address and began handling traffic, but all active client TCP sessions were abruptly dropped, forcing users to re-authenticate. The administrator must update the architecture so that existing connection states persist uninterrupted across failover events. Which of the following solutions should the administrator implement?
A security architect is evaluating hardware security controls for enterprise hardware and embedded system deployments. Match each hardware security component on the left to its corresponding security capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A municipal water utility is re-architecting remote operational telemetry monitoring access for field maintenance engineers. The security architect must enforce Zero Trust Architecture (ZTA) principles to prevent unauthorized lateral movement across operational technology (OT) networks. Which of the following access control implementations best demonstrates the core Zero Trust tenets of explicit verification and least privilege?
Match each resilience and redundancy mechanism on the left with the corresponding operational requirement or architecture scenario on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A logistics enterprise is deploying thousands of handheld mobile terminals to remote distribution staff. The devices operate in physically untrusted environments and store sensitive customer authentication data. The security engineering team mandates that each device must validate system integrity from power-on through operating system initialization using hardware-bound cryptographic measurements, while securely storing full-disk encryption keys on a dedicated cryptoprocessor integrated into the endpoint's motherboard. Which of the following hardware security controls BEST meets this requirement?
A security administrator is troubleshooting a critical network storage appliance in a data center. The appliance features dual internal power supply units (PSUs) to ensure hardware fault tolerance. However, during a recent scheduled power maintenance event on a single electrical circuit, the appliance unexpectedly lost power and shut down. Investigation reveals that both PSUs were plugged into the same rack Power Distribution Unit (PDU). Which of the following infrastructure modifications should the administrator implement to prevent single-circuit power outages from taking the appliance offline?
Match each Identity and Access Management (IAM) architectural component to its primary role within an access evaluation control framework.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An electrical utility provider is deploying smart grid field concentrator units to unmonitored outdoor locations. The units will transmit sensitive metering telemetry and must be protected against physical tampering, unauthorized firmware manipulation, and key extraction. Which of the following hardware security controls should the security architect require for these embedded devices? (Select TWO).
Geçerli olan tümünü seçin
An enterprise is implementing a federated web single sign-on (SSO) solution allowing corporate users to access external cloud applications seamlessly. The architectural requirement mandates using an open standard that relies on XML-based security assertions to transmit authentication state and user attributes from the Identity Provider (IdP) to the Service Provider (SP). Which of the following protocols should the security architect select to meet these requirements?