Question 1 of 15 Governance Risk and Compliance
An architect must ensure the security design supports business goals and regulatory obligations. This alignment is part of what?
A Marketing strategy B Governance, risk, and compliance C Facilities planning D Product packaging
Question 2 of 15 Governance Risk and Compliance
Why does an architect map security controls to specific regulatory requirements?
A To increase the page count of documents B To demonstrate compliance and ensure no requirement is missed C To confuse auditors D To avoid implementing any controls
Question 3 of 15 Governance Risk and Compliance
A risk based architecture prioritizes controls according to what?
A The alphabetical order of systems B The personal preference of one engineer C The newest available product D The likelihood and impact of threats to critical assets
Question 4 of 15 Security Architecture Modeling
A security architecture model such as a reference architecture provides what benefit?
A A reusable blueprint that promotes consistency across designs B A guarantee that no incident will occur C A replacement for all testing D A way to skip requirements
Question 5 of 15 Security Architecture Modeling
When modeling trust zones, why define boundaries between zones of differing sensitivity?
A To control and inspect the traffic that crosses between them B To make the diagram colorful C To allow unrestricted flow everywhere D To remove the need for authentication
Question 6 of 15 Security Architecture Modeling
An architect uses threat modeling during design primarily to do what?
A Select the office location B Identify likely attack paths so the design can mitigate them C Decide the marketing budget D Name the product
Question 7 of 15 Security Architecture Modeling
Which modeling approach helps ensure the architecture addresses confidentiality, integrity, and availability together?
A Focusing only on availability B Considering all three CIA objectives as design drivers C Ignoring integrity to save time D Treating confidentiality as optional
Question 8 of 15 Infrastructure and System Security Architecture
When designing network infrastructure security, why segment the network into zones?
A To increase broadcast traffic B To make every host reachable from anywhere C To limit lateral movement and contain compromises D To remove the need for firewalls
Question 9 of 15 Infrastructure and System Security Architecture
An architect places critical databases in an internal zone with no direct internet access. What principle does this reflect?
A Maximizing convenience for attackers B Publishing data publicly C Defense in depth and minimizing exposure D Removing all access controls
Question 10 of 15 Infrastructure and System Security Architecture
Designing systems so a single component failure does not bring down the service is called what?
A Creating a single point of failure B Removing all backups C Building in redundancy and resilience D Centralizing everything on one server
Question 11 of 15 Infrastructure and System Security Architecture
Why should cryptographic key management be designed into the infrastructure rather than added later?
A Because keys never need rotation B Because encryption is only cosmetic C Because keys can be shared publicly D Because secure key generation, storage, and rotation are foundational to protecting data
Question 12 of 15 Infrastructure and System Security Architecture
A system uses a hardware security module to protect keys. What is the primary benefit?
A Keys are generated and stored in tamper resistant hardware B Keys are printed for staff to memorize C Keys are emailed for backup D Keys are stored in plaintext files
Question 13 of 15 Identity and Access Management Architecture
An identity architecture centralizes authentication so users sign in once for many applications. What is this?
A Single sign on B Separation of duties C Data classification D Network segmentation
Question 14 of 15 Identity and Access Management Architecture
Why should an IAM architecture enforce strong authentication for privileged accounts?
A Because privileged accounts are high value targets whose compromise is severe B Because they only run reports C Because privileged accounts are never attacked D Because they have no special access
Question 15 of 15 Identity and Access Management Architecture
An architect designs periodic access reviews into the IAM lifecycle. What risk does this address?
A Slow network speeds B High electricity costs C Poor screen resolution D Accumulated and stale entitlements known as privilege creep