1. A security architect is evaluating different architectural patterns for a new highly available and resilient system. The system must maintain continuous operation even if a single component fails. Which principle is most directly addressed by implementing redundant components and failover mechanisms?
Security Architecture
A.Single Point of Failure (SPOF) Elimination
B.Defense in Depth
C.Separation of Duties
D.Least Privilege
Show answerAnswer
A. Single Point of Failure (SPOF) Elimination
Implementing redundant components and failover mechanisms directly targets the elimination of Single Points of Failure (SPOFs) by ensuring that no single component's failure can bring down the entire system.
2. A security team is developing a threat hunting hypothesis: 'Adversaries are using legitimate administrative tools (LOLBins) to move laterally within our network, specifically targeting RDP sessions.' Which of the following data sources would be most critical to analyze to validate this hypothesis?
Security Operations
A.Web application firewall (WAF) logs for SQL injection attempts.
B.Endpoint Detection and Response (EDR) telemetry for process execution and network connections.
B. Endpoint Detection and Response (EDR) telemetry for process execution and network connections.
The hypothesis focuses on 'legitimate administrative tools (LOLBins)' and 'lateral movement... targeting RDP sessions'. EDR telemetry provides granular visibility into process execution (to identify LOLBins), network connections (to see RDP traffic), and parent-child process relationships, making it ideal for detecting and analyzing lateral movement and LOLBin usage on endpoints.
3. An organization is designing a new critical infrastructure system that must operate continuously, even if major components fail or are compromised. The security architect is considering principles to ensure the system can withstand such events. Which design principle focuses on the system's ability to maintain operations despite failures or attacks, often through redundancy and isolation?
Security Architecture
A.Resilience
B.Separation of Duties
C.Defense in Depth
D.Least Privilege
Show answerAnswer
A. Resilience
Resilience in security design refers to a system's ability to continue operating, possibly in a degraded but functional state, when faced with failures, attacks, or unexpected conditions. This is often achieved through redundancy, fault tolerance, and isolation.
4. A large enterprise is migrating its on-premises data warehouse to a cloud-native platform. The data warehouse contains petabytes of sensitive customer transaction data, and the migration requires a phased approach. The security architect needs to design a solution that ensures data privacy and compliance with various regulations during the migration process, especially when data is transferred between the on-premises and cloud environments, and while it resides in temporary cloud storage before final integration. Which data security control is paramount for protecting this sensitive data during its journey and temporary residency in the cloud?
Security Architecture
A.Configuring network segmentation within the cloud environment.
B.Utilizing Data Loss Prevention (DLP) solutions on egress points.
C.Implementing strong firewall rules at the cloud perimeter.
D.Applying end-to-end encryption for data in transit and at rest.
Show answerAnswer
D. Applying end-to-end encryption for data in transit and at rest.
End-to-end encryption for data in transit and at rest is paramount for protecting sensitive data during migration to the cloud. This ensures that even if data is intercepted during transfer or accessed from temporary storage, it remains unreadable and protected, directly addressing privacy and compliance requirements.
5. A security analyst is investigating a suspected ransomware infection. They observe encrypted files with a new extension, a ransom note, and a high CPU usage on several endpoints. Further analysis indicates that the ransomware used a complex obfuscation technique to evade signature-based detection. To gain a deeper understanding of the ransomware's decryption mechanism and potentially develop a countermeasure, which advanced forensic technique would be most appropriate?
Security Operations
A.Memory forensics to dump and analyze process memory
B.Reverse engineering the ransomware binary
C.Network packet capture and protocol analysis
D.Static malware analysis using string extraction
Show answerAnswer
B. Reverse engineering the ransomware binary
To understand a ransomware's decryption mechanism, especially when obfuscation is used, reverse engineering the ransomware binary (D) is the most appropriate and often necessary technique. This involves dissecting the code to understand its logic, cryptographic routines, and key management, which can lead to developing decryption tools. While other options provide useful information, they won't reveal the decryption logic itself.
6. A large software company is adopting a 'shift-left' security approach and wants to integrate security testing into its Continuous Integration/Continuous Deployment (CI/CD) pipeline. The primary goal is to identify common security vulnerabilities and coding errors early in the development lifecycle, specifically within the source code itself, before compilation or deployment. Which security testing methodology is BEST suited for this purpose?
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shifting left' by identifying vulnerabilities and coding errors early in the development process, directly from the code base before compilation or deployment.
7. A forensic investigator is analyzing a compromised Linux server. They have created a memory dump and identified several suspicious processes. To determine if any of these processes are attempting to hide their activities by unlinking their executable files, which of the following techniques should the investigator use?
Security Operations
A.Analyze network connections associated with the processes using `netstat` output from the memory dump.
B.Extract the process environment variables to identify suspicious configurations.
C.Look for specific entries in `/var/log/auth.log` that indicate privilege escalation.
D.Examine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.
Show answerAnswer
D. Examine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.
On Linux, when an executable is deleted (unlinked) while a process is still running, the `/proc/<PID>/exe` symbolic link will typically point to a 'deleted' file, and the original file path might not exist on disk. Examining these specific symbolic links and the `cwd` within a memory dump (using tools like Volatility) is the most direct way to detect unlinked executables.
8. A security architect is designing a highly available and resilient system for a critical financial application that processes millions of transactions daily. The system must tolerate the complete failure of an entire geographic region without data loss or significant service interruption. Which architectural pattern is most effective for achieving this objective?
Security Architecture
A.Load balancing across multiple availability zones in a single region
B.Database sharding with eventual consistency
C.Active/Passive clustering within a single data center
D.Multi-region active/active deployment with synchronous data replication
Show answerAnswer
D. Multi-region active/active deployment with synchronous data replication
A multi-region active/active deployment with synchronous data replication ensures that if one entire geographic region fails, another region can immediately take over with no data loss, meeting the requirements for high availability and resilience.
9. A security analyst is performing threat hunting activities within the organization's SIEM. They are specifically looking for signs of a 'living off the land' attack, where attackers use legitimate system tools and processes for malicious purposes. Which of the following log analysis techniques would be most effective for detecting such an attack?
Security Operations
A.Monitoring for unusual process execution patterns and deviations from baselines.
B.Detecting new user account creation and privilege escalation events.
C.Searching for known malicious file hashes in endpoint logs.
D.Analyzing network flow data for connections to known malicious IP addresses.
Show answerAnswer
A. Monitoring for unusual process execution patterns and deviations from baselines.
Living off the land attacks leverage legitimate tools, meaning traditional signature-based detection (like malicious file hashes or known bad IPs) is less effective. Monitoring for unusual process execution patterns and deviations from established baselines is crucial for identifying when legitimate tools are being used in an illegitimate manner.
10. A large enterprise is migrating its legacy monolithic applications to a microservices architecture running on Kubernetes. The security team needs to implement a solution that ensures all inter-service communication within the cluster is mutually authenticated and encrypted, without requiring developers to embed cryptographic logic into each microservice. This solution should also provide fine-grained authorization policies based on service identity. Which component of a service mesh would BEST address these requirements?
Security Engineering
A.API Gateway
B.Ingress Controller
C.Sidecar Proxy
D.Container Network Interface (CNI)
Show answerAnswer
C. Sidecar Proxy
A sidecar proxy, a core component of a service mesh, intercepts all inbound and outbound network traffic for a microservice. It can transparently handle mutual TLS (mTLS) for encryption and authentication, and enforce fine-grained authorization policies based on service identity, without developers needing to modify application code.
11. A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its operational technology (OT) network. To ensure the highest level of security and prevent unauthorized access or modification, all communications between the ICS components and the supervisory control systems must be integrity-protected and cryptographically authenticated. Given the real-time constraints and resource limitations of some ICS devices, which advanced cryptographic primitive would be MOST suitable for ensuring data integrity and authenticity without full encryption?
Security Engineering
A.Hash-based Message Authentication Code (HMAC)
B.RSA Digital Signature Algorithm
C.Elliptic Curve Digital Signature Algorithm (ECDSA)
D.Advanced Encryption Standard (AES)
Show answerAnswer
A. Hash-based Message Authentication Code (HMAC)
The requirement is for data integrity and authenticity without full encryption, especially considering real-time constraints and resource limitations. HMAC (Hash-based Message Authentication Code) provides both data integrity (detects accidental or intentional modification) and authenticity (verifies the sender's identity using a shared secret key) efficiently. AES is for encryption, and ECDSA/RSA are digital signature algorithms that provide non-repudiation in addition to integrity and authenticity but are computationally more expensive than HMAC and might be overkill for resource-constrained ICS devices if non-repudiation is not a strict requirement.
12. A security architect is tasked with implementing data security for a new application that processes credit card information. To achieve PCI DSS compliance, the architect needs to ensure that sensitive authentication data (SAD) is never stored after authorization, even if encrypted. Which data security control BEST addresses this specific requirement?
Security Architecture
A.Tokenization
B.Data Minimization
C.Format-Preserving Encryption (FPE)
D.Data Masking
Show answerAnswer
A. Tokenization
Tokenization replaces sensitive data (like primary account numbers or SAD) with a non-sensitive equivalent (a token) that has no exploitable meaning or value. For PCI DSS, specifically, SAD must not be stored after authorization, even if encrypted. Tokenization achieves this by ensuring the original SAD is never stored by the merchant system, only a non-sensitive token, and the actual SAD is held in a secure, compliant token vault.
13. A security analyst is investigating a suspected data breach involving sensitive customer information. The forensic investigation reveals that an attacker gained access through a vulnerable web application, escalated privileges, and then maintained persistence by injecting malicious code into a legitimate system process that restarts automatically. Which of the following MITRE ATT&CK tactics does this persistence method MOST directly align with?
Security Operations
A.Initial Access
B.Persistence
C.Defense Evasion
D.Execution
Show answerAnswer
B. Persistence
Injecting malicious code into a legitimate system process that restarts automatically is a classic method for maintaining persistence on a compromised system. This ensures the attacker retains access even after reboots or system resets, directly aligning with the 'Persistence' tactic in MITRE ATT&CK.
14. A financial institution is evaluating its enterprise-wide risk management program. The Chief Risk Officer (CRO) wants to move beyond simply identifying risks to understanding the potential financial impact of various cyber events and prioritizing mitigation efforts based on this impact. Which of the following approaches should the CRO implement to achieve this objective?
Governance, Risk and Compliance
A.Quantitative Risk Assessment
B.Qualitative Risk Assessment
C.Compliance Checklist Review
D.Risk Register Maintenance
Show answerAnswer
A. Quantitative Risk Assessment
A quantitative risk assessment focuses on assigning monetary values to assets, threats, and vulnerabilities to calculate the potential financial loss from a cyber event. This allows the CRO to prioritize mitigation based on actual financial impact, moving beyond subjective qualitative ratings.
15. A security architect is designing an information security program for a critical infrastructure organization. The organization needs a framework that provides a flexible, risk-based approach to cybersecurity, allowing for adaptation to evolving threats and technologies, while also enabling communication of cybersecurity risk to a wide range of stakeholders. Which framework is BEST suited for this requirement?
Governance, Risk and Compliance
A.COBIT
B.NIST Cybersecurity Framework (CSF)
C.HIPAA
D.ISO/IEC 27001
Show answerAnswer
B. NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) is designed to be flexible, adaptable, and risk-based, making it suitable for critical infrastructure. It provides a common language for communicating cybersecurity risk among stakeholders at all levels, from technical teams to senior management, and is not prescriptive, allowing organizations to tailor it to their specific needs and evolving threat landscape.
16. A global healthcare provider is deploying a new patient management system across multiple countries. Due to varied and strict data privacy regulations (e.g., GDPR in Europe, HIPAA in the US, local laws in Asia), the architecture must ensure that patient data collected in a specific region remains stored and processed exclusively within that region's geographical boundaries. Which architectural principle directly addresses this requirement?
Security Architecture
A.Data Redundancy
B.Data Minimization
C.Data Localization (Data Residency)
D.Data Obfuscation
Show answerAnswer
C. Data Localization (Data Residency)
Data Localization, also known as Data Residency, is the architectural principle that mandates sensitive data to be stored and processed within specific geographical boundaries to comply with local laws and regulations. This directly addresses the requirement for patient data to remain within its region of origin.
17. A financial institution is designing a new payment processing system that must comply with strict regulatory requirements for data integrity and non-repudiation of transactions. Each transaction must be verifiably linked to the originating party and prove that it has not been altered since it was created. Which cryptographic technique is essential for meeting these requirements?
Security Architecture
A.Symmetric encryption
B.Hashing with a salt
C.Digital Signatures
D.Homomorphic encryption
Show answerAnswer
C. Digital Signatures
Digital signatures provide data integrity (proof of no alteration) and non-repudiation (verifiable link to the originator) by using asymmetric cryptography to sign a hash of the data with the sender's private key.
18. A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to identify and remediate security vulnerabilities in their custom-developed code as early as possible, ideally before the code is even compiled or deployed. Which security testing tool is best suited for this objective?
Security Architecture
A.Static Application Security Testing (SAST)
B.Interactive Application Security Testing (IAST)
C.Dynamic Application Security Testing (DAST)
D.Penetration Testing
Show answerAnswer
A. Static Application Security Testing (SAST)
Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shift-left' as it can identify vulnerabilities early in the development lifecycle, even before the application is compiled or deployed, aligning with the goal of early detection.
19. A security engineer is hardening a Windows Server that hosts a critical enterprise application. The organization's security policy requires that all system-level processes and services run with the minimum necessary privileges to perform their functions. Which of the following Windows features or concepts is MOST relevant to implementing this principle of least privilege for services?
Security Engineering
A.User Account Control (UAC)
B.Service Accounts and Managed Service Accounts (MSAs/gMSAs)
C.Windows Firewall with Advanced Security
D.Data Execution Prevention (DEP)
Show answerAnswer
B. Service Accounts and Managed Service Accounts (MSAs/gMSAs)
Service Accounts and especially Managed Service Accounts (MSAs) or group Managed Service Accounts (gMSAs) in Windows are specifically designed to allow services to run under dedicated, low-privilege identities. MSAs/gMSAs automate password management and simplify service principal name (SPN) management, ensuring that services operate with only the permissions required, thereby adhering to the principle of least privilege. This directly addresses the requirement for system-level processes and services to run with minimum necessary privileges.
20. A large e-commerce company is implementing a new AI-powered recommendation engine. During the development and testing phases, the data science team discovers that the engine consistently recommends higher-priced items to users in certain postal codes, regardless of their stated preferences or browsing history, potentially leading to unfair pricing for specific demographic groups. Which ethical concern related to AI is MOST directly highlighted by this discovery?
Governance, Risk and Compliance
A.AI Accountability
B.AI Transparency
C.AI Privacy
D.AI Fairness
Show answerAnswer
D. AI Fairness
The scenario describes an AI system exhibiting algorithmic bias, where certain demographic groups (inferred by postal codes) receive different, potentially disadvantageous, treatment (higher-priced recommendations). This directly relates to AI Fairness, which aims to ensure AI systems provide equitable outcomes and do not discriminate or perpetuate bias.
21. A security architect is designing a system for a highly sensitive research facility that processes classified data. The system must enforce strict isolation between different security domains, even at the hardware level, to prevent any data leakage or unauthorized access. Which specialized system architecture is MOST appropriate for achieving this level of isolation?
Security Engineering
A.Hardware-enforced separation (e.g., Multiple Independent Levels of Security/MILS)
B.Virtualization with a Type 2 hypervisor
C.Cloud-based multi-tenancy with strong access controls
D.Containerization (e.g., Docker, Kubernetes)
Show answerAnswer
A. Hardware-enforced separation (e.g., Multiple Independent Levels of Security/MILS)
Hardware-enforced separation, such as MILS (Multiple Independent Levels of Security), provides the highest degree of isolation by physically or logically segregating components at the silicon level, ensuring distinct security domains cannot interfere with each other. This is crucial for classified environments where even hypervisor-level vulnerabilities are unacceptable.
22. A global organization is implementing a new customer relationship management (CRM) system that will store personally identifiable information (PII) for customers across various jurisdictions, each with different data residency and privacy regulations. The security architect needs to design a data architecture that ensures compliance while optimizing performance. Which approach is MOST suitable for addressing these complex requirements?
Security Architecture
A.Centralizing all PII data in a single, highly secured data center in a neutral country.
B.Utilizing a globally distributed database with strong encryption, irrespective of data origin.
C.Anonymizing all PII data before storage and only de-anonymizing for specific authorized processes.
D.Implementing data localization by storing PII within the geographical boundaries of its origin.
Show answerAnswer
D. Implementing data localization by storing PII within the geographical boundaries of its origin.
Data localization, or data residency, is the practice of storing data within the geographical borders of its origin. This directly addresses legal and regulatory requirements for data residency and privacy, which vary significantly across jurisdictions, ensuring compliance for PII in a global organization, even if it might add complexity to performance optimization.
23. A global enterprise is implementing a Zero Trust architecture across its highly distributed network, which includes on-premises data centers, multiple cloud providers, and remote worker endpoints. A key challenge is establishing and verifying the identity of users and devices, and continuously evaluating their trustworthiness before granting access to resources. Which IAM protocol or framework is BEST suited to facilitate this continuous verification and dynamic policy enforcement across such a diverse and distributed environment?
Security Engineering
A.Lightweight Directory Access Protocol (LDAP)
B.OAuth 2.0 / OpenID Connect (OIDC)
C.Security Assertion Markup Language (SAML)
D.Kerberos
Show answerAnswer
B. OAuth 2.0 / OpenID Connect (OIDC)
OAuth 2.0, primarily for authorization, combined with OpenID Connect (OIDC), for authentication, provides a flexible and extensible framework for identity and access management across diverse environments. Its token-based approach and ability to integrate with various identity providers make it ideal for continuous verification and dynamic policy enforcement in a Zero Trust model, especially with distributed cloud and remote access.
24. A global e-commerce company is migrating its entire infrastructure to a multi-cloud environment. The security team needs to establish a unified security posture, enforce consistent policies, and gain centralized visibility across AWS, Azure, and Google Cloud Platform while maintaining compliance with regional data residency laws. Which integrated security approach is best suited for this complex scenario?
Security Architecture
A.Implementing native security services independently on each cloud platform.
B.Utilizing a Security Information and Event Management (SIEM) system with cloud connectors.
C.Deploying a Cloud Security Posture Management (CSPM) solution with multi-cloud support.
D.Establishing a site-to-site VPN between each cloud provider and an on-premises security appliance.
Show answerAnswer
C. Deploying a Cloud Security Posture Management (CSPM) solution with multi-cloud support.
A CSPM solution with multi-cloud support is specifically designed to address the challenges of consistent policy enforcement, compliance, and visibility across multiple cloud providers. It automates the identification of misconfigurations and security risks, ensuring a unified security posture, which native services or SIEMs alone cannot fully achieve for policy enforcement across heterogeneous environments.
25. A security architect is designing a new cloud-based application and needs to ensure that sensitive data handled by the application is protected both in transit and at rest. The application will interact with several microservices and store data in a NoSQL database. Which combination of cryptographic controls should the architect prioritize to meet these requirements?
Security Operations
A.HTTPS for data in transit and hardware security modules (HSMs) for key management.
B.TLS for data in transit and client-side encryption with strong access controls for data at rest.
C.VPN for data in transit and full disk encryption for data at rest.
D.SSH for data in transit and symmetric encryption for data at rest.
Show answerAnswer
B. TLS for data in transit and client-side encryption with strong access controls for data at rest.
TLS (Transport Layer Security) is the standard for securing data in transit over networks, commonly used by microservices. Client-side encryption ensures that data is encrypted before it leaves the application and is stored in the NoSQL database, offering stronger protection than database-managed encryption, especially when combined with strong access controls.
An architectural principle focused on identifying and mitigating any single component or logical path whose failure would cause the entire system or service to become unavailable.
Achieved through redundancy, clustering, and failover.
Crucial for high availability and business continuity.
Applies to hardware, software, network paths, and data.
Endpoint Detection and Response (EDR) solutions collect and analyze endpoint data (process execution, network connections, file system changes) to detect, investigate, and respond to threats like lateral movement and LOLBin abuse.
Provides granular endpoint visibility.
Detects anomalous process behavior.
Tracks network connections originating from endpoints.
A resilient architecture is designed to withstand and recover from various failures, attacks, or unexpected conditions, maintaining its core functionality and operations even when components are compromised or unavailable.
Focuses on continuous operation despite disruptions.
Achieved through redundancy, fault tolerance, isolation, graceful degradation.
Adapts to changing conditions and recovers quickly.
The practice of encrypting data at its origin and decrypting it only at its final destination, ensuring it remains protected throughout its entire lifecycle, including in transit and at rest.
Protects data confidentiality from source to destination.
Crucial for sensitive data, especially during cloud migrations.
Combines encryption for data in transit (e.g., TLS) and at rest (e.g., disk encryption).
The process of deconstructing executable software (binaries) to understand its inner workings, algorithms, and logic, without access to the source code. It's essential for analyzing complex malware, especially when obfuscation is present, to develop countermeasures or identify vulnerabilities.
Static Application Security Testing (SAST) is a white-box testing method that analyzes an application's source code, bytecode, or binary code without actually executing the application, to identify security vulnerabilities and coding errors.
The `/proc` filesystem in Linux is a virtual filesystem that provides an interface to kernel data structures, allowing forensic investigators to examine running processes, their memory maps, open files, and other runtime information.
The practice of having duplicate critical systems and data in geographically separate locations to ensure continuous operation and data availability in the event of a regional disaster.
Protects against large-scale outages (e.g., natural disasters).
Often involves active/active or active/passive deployments across regions.
Requires robust data replication strategies (synchronous for zero data loss).
An attack technique where adversaries use legitimate, pre-installed tools and features already present on a compromised system (e.g., PowerShell, WMI, PsExec) to carry out malicious activities, making detection difficult.
A lightweight proxy deployed alongside each application container (microservice) in a Kubernetes pod. It intercepts all network traffic to and from the microservice, offloading network and security functions from the application logic.
Enables transparent mutual TLS (mTLS) between services.
Enforces traffic policies and authorization.
Removes security and network concerns from application code.
HMAC (Hash-based Message Authentication Code) is a specific type of Message Authentication Code (MAC) involving a cryptographic hash function and a secret cryptographic key. It is used to simultaneously verify both the data integrity and the authenticity of a message.
Provides both data integrity and authenticity.
Uses a shared secret key.
More efficient than digital signatures for integrity/authenticity.
Tokenization is a data security technique where sensitive data (like credit card numbers or Sensitive Authentication Data - SAD) is replaced with a unique, non-sensitive identifier called a token. For PCI DSS, this ensures SAD is never stored by the merchant after authorization, as only the token is retained.
Replaces sensitive data with a non-sensitive token.
Original data stored in a secure token vault (or discarded for SAD).
Crucial for PCI DSS compliance, especially for SAD.
The MITRE ATT&CK 'Persistence' tactic describes techniques adversaries use to maintain their foothold in a system across reboots, changes in credentials, or other interruptions.
Ensures continued access to a compromised system.
Often involves modifying system startup mechanisms, creating new user accounts, or injecting code.
An objective, data-driven approach to risk assessment that assigns monetary values to assets, threats, vulnerabilities, and the potential losses from security incidents.
Uses formulas like ALE = SLE x ARO to calculate financial risk.
Provides a clear financial justification for security investments.
Requires detailed data on asset values, incident frequency, and recovery costs.
The requirement that certain data must be stored and processed within the geographical borders of a specific country or region, often due to legal or regulatory mandates.
Ensures compliance with national data protection laws.
Impacts cloud deployment strategies and data transfer mechanisms.
Requires careful planning for global applications and services.
A cryptographic technique used to verify the authenticity and integrity of digital messages or documents, providing assurance of the sender's identity (non-repudiation) and proof that the data has not been altered in transit.
Uses asymmetric cryptography (private key to sign, public key to verify).
Provides data integrity and non-repudiation.
Often involves hashing the message before signing.
Managed Service Accounts (MSAs) and group Managed Service Accounts (gMSAs) are special types of domain accounts in Active Directory designed to provide automatic password management, simplified SPN management, and delegation of management to other administrators, for services and scheduled tasks.
Automate password rotation for service accounts.
Provide principle of least privilege for services.
Eliminate need for manual password updates for services.
A system architecture that uses hardware mechanisms to create provably isolated partitions, ensuring distinct security domains cannot interfere with each other.
Highest level of isolation.
Used for classified or safety-critical systems.
Prevents side-channel attacks and hypervisor escapes.
OAuth 2.0 is an authorization framework allowing third-party applications to obtain limited access to an HTTP service. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, enabling clients to verify the identity of the end-user.
A security solution that continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing remediation guidance and enforcing security policies.
Automates identification of security misconfigurations across cloud resources.
Ensures continuous compliance with industry standards and regulations.
Provides centralized visibility and reporting for multi-cloud environments.
The process of encrypting data on the user's or application's device before it is transmitted to a cloud service or stored in a database, ensuring that the cloud provider never has access to unencrypted sensitive data.
User/application controls the encryption keys.
Protects data even if the cloud provider is compromised.
Security Service Edge (SSE) is a cloud-centric security model that converges security services including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Firewall-as-a-Service (FWaaS) into a unified, cloud-delivered platform.
Delivers security as a cloud service.
Provides consistent policy enforcement for users, devices, and applications.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.