Security Architecture
405 soru
A security architect is designing a high-availability solution for a critical authentication service distributed across two geographically separated cloud availability zones. The solution must support dynamic redirection of client traffic during an outage and ensure zero data loss for active user sessions during a database failover. Which of the following technical controls should be included in the design to meet these resilience requirements? (Select TWO.)
Geçerli olan tümünü seçin
Match each hardware security mechanism on the left to its corresponding primary functional capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial services organization is designing a modern Identity and Access Management (IAM) architecture. The organization needs to grant a third-party analytics application permission to read transaction history from its internal API on behalf of authenticated end users. Company security policy mandates that end-user credentials must never be exposed to or stored by the third-party application, and access rights must be scoped specifically for API data delegation without transferring identity authentication assertions. Which of the following identity and access management frameworks should the security architect select to meet these requirements?
A biotechnology enterprise is updating its network security posture to protect cloud-hosted genomic research databases accessed by remote scientists. The organization intends to implement Zero Trust Architecture (ZTA) principles to replace legacy perimeter defenses. Which of the following requirements must be implemented to align with core Zero Trust tenets? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise web application experienced an unrecoverable infrastructure failure at its primary facility. The incident response team must execute the disaster recovery plan to activate the secondary warm site and minimize service disruption. In what chronological order should the administrator execute the following steps to complete the failover securely while preserving data integrity?
Öğeleri doğru sıraya koymak için sürükleyin
An organization is establishing hardware security specifications for edge computing appliances deployed in remote, physically untrusted locations. The security architect must ensure cryptographic keys stored on hardware cannot be extracted via physical chip probing, and device identities cannot be duplicated onto unauthorized hardware. Which of the following hardware security controls should be implemented to meet these specific requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise security architect is designing an updated Identity and Access Management (IAM) architecture to support dynamic, fine-grained authorization across microservices while automating user account lifecycles across cloud services. Which of the following components or standards should be incorporated into the architecture to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security architect is designing a multi-tenant enterprise environment hosted on shared physical hardware. The corporate compliance policy requires strict hardware-enforced memory separation and workload isolation between high-risk third-party microservices and sensitive internal data systems to prevent kernel-level privilege escalation attacks. Which of the following deployment architectures BEST satisfies this security requirement?
An enterprise security architect is aligning network isolation mechanisms with specific high-assurance business requirements across diverse deployment environments. Match each network segmentation approach on the left with its defining architectural implementation requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An administrator is designing a multi-tiered secure network path to allow external management traffic to reach a critical database server. Arrange the network segments in the correct order that incoming administration traffic must traverse, starting from the least secure network segment to the most secure network segment.
Öğeleri doğru sıraya koymak için sürükleyin
A security administrator is evaluating deployment options for an enterprise application hosted on a shared physical server. The organization requires full hardware abstraction and distinct operating system kernels for each workload to ensure complete isolation between tenants. Which of the following virtualization or containerization technologies best meets this requirement?
A biomedical research facility hosts legacy laboratory automation equipment running unpatchable operating systems. The facility must export real-time telemetry data from these legacy systems to an internal analytics data lake while simultaneously granting temporary remote access to an off-site maintenance vendor. Which of the following network architecture designs best isolates the legacy equipment while enabling these required operational functions?
A bio-pharmaceutical consortium deploys a joint machine learning analytics platform hosted within a Community Cloud environment shared exclusively among vetted research institutions. Under the cloud shared responsibility model, which of the following operational tasks is strictly the sole responsibility of each participating research organization?
A bio-pharmaceutical research laboratory is deploying an automated, event-driven genomic data processing pipeline using a serverless Function-as-a-Service (FaaS) model hosted on a public cloud platform. In this architecture, cloud functions are automatically invoked whenever new dataset files are uploaded to cloud storage buckets. Under the cloud shared responsibility model, which TWO of the following security tasks are the explicit responsibility of the customer organization?
Geçerli olan tümünü seçin
A security engineer is performing a threat modeling analysis on a hybrid hypervisor host node that simultaneously runs both tenant Virtual Machines (VMs) managed by a Type 1 hypervisor and application containers running directly on the host operating system kernel. A zero-day privilege escalation vulnerability is discovered in the core host operating system kernel's memory management subsystem. Which of the following statements accurately evaluates the primary security risk distinction between the container workloads and the virtual machine workloads under this threat condition?
A DevSecOps engineer is hardening a shared Linux host operating system running multiple containerized microservices for a financial application. Although process namespaces successfully prevent containers from viewing processes outside their environment, a security audit reveals that a compromised container could still invoke unauthorized kernel functions directly against the shared host kernel. Which of the following technical security controls should the engineer implement to restrict the specific system calls available to the containerized applications?
An enterprise security architect is designing network isolation controls for a corporate software development environment. The architecture must prevent lateral movement between developer workstations on the same local subnet while restricting direct administrative connections from developer machines to automated build servers. Which of the following network design strategies should the architect implement to achieve these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An e-commerce enterprise needs to process customer payment cards while ensuring that actual Primary Account Numbers (PANs) are never stored in internal application databases. The security architecture replaces sensitive card numbers with non-sensitive surrogate values while storing the real card numbers in a secure external vault. Which of the following data protection mechanisms is being described?
An IT administrator needs to deploy multiple isolated application services on a single physical host while minimizing memory overhead and eliminating the need to install a separate guest operating system for each service. Which of the following technologies best fulfills this requirement?
Match each storage security control mechanism to its corresponding enterprise architectural objective.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler