Security Architecture & Engineering Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Architecture & Engineering flashcards as text
Which security architecture principle ensures that a compromised component cannot affect the security of the entire system?
Answer: Compartmentalization
Compartmentalization isolates system components so a breach in one area does not propagate to others.
In the context of CAP, what does 'trustworthiness' of an information system primarily depend on?
Answer: Security functionality and assurance
Trustworthiness combines security functionality (what the system does) with assurance (confidence that it does it correctly).
A system uses a reference monitor to mediate all access to objects. Which property ensures the reference monitor cannot be bypassed?
Answer: Non-bypassability
Non-bypassability means every access request must go through the reference monitor with no alternative path available.
Which cryptographic mode of operation provides both confidentiality and authentication in a single pass?
Answer: GCM (Galois/Counter Mode)
GCM is an authenticated encryption mode that simultaneously provides confidentiality and integrity/authentication.
An organization implements mandatory access control (MAC) based on data classification levels. Which model best describes this approach?
Answer: Bell-LaPadula Confidentiality Model
Bell-LaPadula enforces confidentiality using classification levels with 'no read up, no write down' rules.
What is the primary security concern with using ECB mode for encrypting large amounts of data?
Answer: Identical plaintext blocks produce identical ciphertext blocks
ECB encrypts identical plaintext blocks into identical ciphertext blocks, revealing patterns in the data.
In zero-trust architecture, which principle replaces traditional perimeter-based security?
Answer: Never trust, always verify
Zero-trust operates on 'never trust, always verify,' requiring continuous authentication regardless of network location.