Security Architecture
405 soru
A defense technology organization is implementing Zero Trust Architecture (ZTA) for field operations. Mobile tactical command units must access centralized intelligence databases across untrusted wireless channels. To strictly adhere to Zero Trust principles, the architecture must decouple control plane policy evaluation from data plane enforcement. Which of the following implementations correctly demonstrates this architectural separation?
A financial organization is migrating an existing legacy internal application to a public Infrastructure as a Service (IaaS) environment. Under the cloud shared responsibility model, which of the following security management tasks are the direct responsibility of the organization? (Select TWO.)
Geçerli olan tümünü seçin
A smart manufacturing facility is updating its industrial control network to align with Zero Trust Architecture (ZTA) principles. Currently, field sensor nodes and automated robotic assembly controllers communicate freely within an internal operational technology (OT) network segment once inside the network perimeter. Which of the following architectural modifications best implements the core Zero Trust principle of continuous explicit verification for these device communications?
During a security incident investigation on an enterprise server host, security analysts discover that an attacker exploited a vulnerability within a containerized application process to inject a malicious kernel module. This kernel module allowed the attacker to escape the application environment, gain full root control over the underlying host operating system, and access data across all neighboring tenant applications on that physical node. Which of the following fundamental architectural weaknesses enabled this cross-tenant host compromise, and what control provides the required isolation boundary?
A network security architect is designing an ingress traffic transit flow for an enterprise application processing sensitive financial data. External client traffic must traverse multiple physical and logical security zones to interact with the backend database while enforcing strict North-South and East-West control boundaries. Arrange the following network security architecture traversal steps in the correct sequential order from the initial external inbound packet arrival to the final payload processing at the database host.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise organization recently deployed a critical application database server equipped with redundant hot-swappable power supplies and a RAID 5 disk array to fulfill a high-availability SLA. Following a malicious script execution, essential database tables were logically corrupted and encrypted. The network administrator confirmed that all hard drives and hardware components remained fully operational with active green status indicators, yet data restoration from the local array was impossible. Which of the following best explains why this high-availability configuration failed to preserve data access, and what control should be implemented?
A security engineer is configuring an automated failover workflow for an active-passive high-availability database cluster to prevent split-brain conditions and ensure data integrity during an ungraceful primary node failure. Arrange the operational steps in the correct chronological order from initial failure detection to full service restoration on the standby node.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise financial platform maintains an active-passive database cluster across two data centers using synchronous storage replication to satisfy a Recovery Point Objective (RPO) of zero. During a security architecture review, an auditor notes that while synchronous replication protects against site-level hardware failure, a ransomware infection or database corruption on the primary node will instantly mirror to the secondary node, destroying operational integrity across both sites. Which of the following technical solutions best maintains high availability while ensuring recovery capability against logical data corruption?
An enterprise is migrating its customer database to a Platform as a Service (PaaS) cloud environment. During the architectural design phase, the security team must document operational duties in accordance with the cloud shared responsibility model. Which of the following responsibilities remains strictly with the customer organization in a PaaS deployment?
Match each cloud service model to its primary operational responsibility boundary.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each organizational security management requirement to the cloud service model where the customer retains primary operational responsibility for implementing that control.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security architect is reviewing the security boundaries for a newly deployed application utilizing Function as a Service (FaaS) within a public cloud provider. To ensure governance and compliance, the security team must establish clear operational boundaries under the cloud shared responsibility model. Which of the following management tasks remains the primary responsibility of the customer in this serverless architecture deployment?
A consortium of regional financial institutions establishes a shared cloud infrastructure to process payment transactions while meeting common regulatory compliance standards. Which of the following characteristics accurately describe this cloud deployment model? (Select TWO.)
Geçerli olan tümünü seçin
A company adopts a cloud solution where the cloud service provider maintains the underlying hardware, network infrastructure, operating systems, and runtime execution environments. The company's developers are only responsible for uploading and configuring their application code and data. Which cloud service model is described in this scenario?
A healthcare provider is adopting a multi-tenant Software as a Service (SaaS) application to manage patient records across several remote clinics. The security architect must ensure that sensitive patient data transmitted to and from the SaaS application is monitored for policy violations, encrypted in transit, and protected against unauthorized data exfiltration without modifying the underlying cloud provider infrastructure. Which of the following solutions should the security team implement to meet these governance and control requirements?
Match each cloud computing service model to the primary architectural boundary managed by the cloud service provider.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security architect is establishing an operational governance framework for cloud adoption across multiple business units. Match each security administration task on the left with the primary responsible party under the cloud shared responsibility model on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization hosts a customer database in a cloud environment where the cloud provider manages the physical server hardware, data center access, and hypervisor virtualization layer. The organization's internal IT team remains responsible for configuring, updating, and patching the guest operating systems and application software. Which cloud service model is the organization currently using?
An enterprise organization is migrating its internal customer portal to a cloud environment utilizing a Platform as a Service (PaaS) deployment model. Under the cloud Shared Responsibility Model, which of the following security tasks remains the primary responsibility of the enterprise organization?
An organization is deploying a serverless Function-as-a-Service (FaaS) application in a public cloud environment to process customer images. According to the cloud Shared Responsibility Model, which TWO of the following tasks remain the responsibility of the customer? (Select TWO)
Geçerli olan tümünü seçin