TechNuggets Academy

Security Architecture

Free CompTIA SecurityX practice — 6 questions on Security Architecture, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Architecture
A multinational company with a remote workforce spread across 40 countries wants to consolidate SWG, CASB, ZTNA, and FWaaS functions into a single cloud-delivered service, eliminating backhaul of remote-user traffic to on-premises data centers for internet-bound traffic. Which architecture BEST meets this requirement?
SASE converges SD-WAN networking with SWG, CASB, ZTNA, and FWaaS delivered from distributed cloud PoPs close to users, eliminating backhaul while enforcing consistent security policy globally.
Question 2 of 6 · Security Architecture
A financial services firm operating under GDPR replicates customer data across multiple cloud regions and multiple backup tiers. When a customer exercises the 'right to erasure,' the firm must render that customer's data irrecoverable everywhere without physically destroying shared storage media used by other tenants. Which technique BEST satisfies this requirement?
Per-tenant encryption keys allow cryptographic erasure: destroying the key renders all copies of that customer's data (across regions and backups) unrecoverable without needing to locate and wipe every physical copy.
Question 3 of 6 · Security Architecture
Per NIST SP 800-207, an enterprise wants its zero trust architecture to continuously reevaluate access based on real-time device posture, location, and behavioral risk score, rather than trusting a session established at initial login. Which configuration achieves this?
Zero trust requires continuous, per-request authorization: the PEP must consult the PDP on every access attempt, factoring in dynamic risk signals, rather than relying on a one-time authentication decision.
Question 4 of 6 · Security Architecture
A company's ML-based fraud detection model retrains continuously on a stream of incoming customer transaction data. The security team is concerned an adversary could inject crafted malicious samples into the training pipeline to cause the model to systematically misclassify future fraudulent transactions as legitimate. Which architectural control BEST mitigates this risk?
Training data (poisoning) attacks require controls at data ingestion: provenance tracking, statistical/anomaly validation, and human review before untrusted samples are allowed into the retraining set, preventing malicious data from corrupting the model.
Question 5 of 6 · Security Architecture
A healthcare organization requires an RPO of 15 minutes and RTO of 1 hour for its EHR systems, and must ensure backups survive an attacker who has already obtained domain administrator credentials and attempts to encrypt or delete backup data. Which architecture BEST meets these requirements?
CDP satisfies the 15-minute RPO, and immutable object storage with a separate identity plane (no shared domain trust) ensures a domain-admin-level attacker cannot alter or delete backups, satisfying both the recovery objectives and ransomware resilience requirement.
Question 6 of 6 · Security Architecture
Which statement BEST differentiates microsegmentation from traditional network macrosegmentation (VLAN/subnet-based) in an enterprise zero trust architecture?
Microsegmentation enforces fine-grained, workload/identity-aware policy (frequently via host-based agents or software-defined controls) that isolates individual workloads regardless of subnet, whereas macrosegmentation creates broader trust zones bounded by VLANs or subnets.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →