Security Architecture
405 soru
A healthcare organization must connect legacy diagnostic imaging equipment running unsupported operating systems to the enterprise network. The architecture must allow authorized workstations to retrieve image files while preventing lateral movement if an imaging system is compromised, and restricting administrative access to authenticated technicians. Which of the following network design strategies best fulfills these security requirements?
To enforce defense-in-depth across a multi-tenant cloud infrastructure hosting both virtual machines and container workloads, a platform security engineer must align security mechanisms with their specific operational boundaries. Match each virtualization or containerization technology on the left with its primary isolation boundary or resource control capability on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A financial institution requires a storage security architecture for its high-performance database cluster. The design must protect data at rest against physical drive theft from the data center without incurring host operating system processor overhead, while centralizing cryptographic key management inside a dedicated tamper-resistant hardware appliance. Which of the following solutions best satisfies these security and architectural requirements?
An autonomous manufacturing enterprise is transitioning its edge-compute microservices and industrial IoT telemetry pipeline to a Zero Trust Architecture (ZTA). A security architect must define control plane and data plane operational requirements to enforce core Zero Trust tenets across all component communications.
Which of the following architectural requirements MUST be implemented to strictly align with Zero Trust Architecture principles? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is configuring host-level hardening for an application running in a Linux container environment. Which of the following security mechanisms directly restrict container resource usage and limit accessible host kernel system calls? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator is configuring runtime security settings for a container execution host that processes untrusted third-party workloads. Which TWO of the following security controls should be implemented to reduce the kernel attack surface and prevent persistent host filesystem modifications during container execution?
Geçerli olan tümünü seçin
A financial services company hosts multi-tenant microservices handling sensitive transaction processing. Following a penetration test, security assessors demonstrated that a compromised container could exploit a host Linux kernel vulnerability to gain root privileges on the underlying host OS, compromising adjacent containers. To mitigate this specific attack vector while preserving container deployment automation, which of the following controls should the security team implement?
Match each storage security and data protection mechanism to its primary enterprise operational control function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An industrial manufacturing plant operates a Safety Instrumented System (SIS) to control physical emergency shutdown valves. The security architecture team must forward real-time operational telemetry from the SIS domain to a cloud-based enterprise monitoring platform. However, regulatory standards mandate that no network path can exist that allows incoming commands or external traffic to reach the safety controllers under any circumstances. Which of the following network segmentation controls best satisfies this requirement?
A security architect is updating an enterprise data protection framework to address regulatory compliance and storage security requirements across cloud and on-premises infrastructure. Match each data protection technology to the enterprise operational requirement it primarily fulfills.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A fintech enterprise is redesigning its cloud-native payment gateway architecture to achieve PCI-DSS compliance. The security architecture must restrict lateral movement between individual microservices inside the cardholder data environment (CDE), enforce strict inline policy inspection for outbound internet-bound management connections, and eliminate reliance on internal network location trust. Which of the following network architecture controls should the security team implement to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare technology organization is designing a data protection architecture to archive multi-terabyte patient records in a cloud-based storage repository. Regulatory mandates require that the enterprise security team maintain exclusive physical control over key generation, rotation, and revocation lifecycle operations. Additionally, the bulk encryption mechanism must support high-throughput processing for mass ingestion without delegating root key custody to the cloud service provider. Which of the following storage security architecture configurations best satisfies both performance requirements and regulatory key ownership constraints?
An organization is configuring a shared Linux host operating system to execute unmanaged containerized microservices for multiple untrusted third parties. The security team must minimize the attack surface of the shared host kernel and prevent one tenant's containerized process from inspecting or interacting with processes of another tenant. Which TWO of the following mechanisms directly accomplish these security goals?
Geçerli olan tümünü seçin
Match each virtualization and containerization security mechanism on the left with its primary operational function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security architect is designing a high-availability infrastructure across two geographically separated cloud regions for a critical financial transactions platform. The business impact analysis specifies a Recovery Point Objective () of near-zero () and a Recovery Time Objective () of less than . The design must prevent split-brain condition states during network partitions and ensure continuous operation during full regional outage scenarios. Which TWO of the following architecture controls or configurations must be combined to meet these strict availability, consistency, and resilience requirements? (Select TWO.)
Geçerli olan tümünü seçin
A system administrator is evaluating deployment options for an enterprise workload. Which of the following fundamental architectural characteristics distinguishes application containers from virtual machines?
An enterprise health technology organization is deploying a high-throughput centralized database storage system processing millions of protected health information (PHI) records daily. Compliance standards mandate hardware-level protection for cryptographic key management where master keys are non-exportable and tamper-resistant. Additionally, data-at-rest bulk block encryption performance overhead must be offloaded directly to dedicated disk hardware, preventing media encryption keys from residing in host operating system memory. Which of the following storage security architectures satisfies both the performance and key isolation requirements?
An enterprise security architect is establishing operational boundaries across a multi-cloud enterprise ecosystem. Match each cloud security implementation task on the left with the corresponding cloud service model on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is deploying new laptop computers to remote workers and wants to store full-disk encryption keys securely within dedicated microcontrollers soldered directly onto each computer motherboard. Which hardware security component provides this local cryptoprocessor functionality for device integrity verification and key storage?
Match each hardware security mechanism to its primary security function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler