Security Architecture Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Architecture flashcards as text
Which security architecture approach involves treating security infrastructure as code, enabling automated, repeatable, and version-controlled security deployments?
Answer: Infrastructure as Code (IaC) security with policy-as-code enforcement
Infrastructure as Code combined with policy-as-code allows security controls to be defined, versioned, tested, and automatically enforced across environments, eliminating configuration drift and manual errors.
A CISO is assessing the security architecture of a third-party SaaS provider. Which architectural control gives the CISO the greatest assurance about the provider's security without direct access to their systems?
Answer: Obtaining and reviewing a current SOC 2 Type II report or ISO 27001 certification with access to the full audit report
A SOC 2 Type II report provides independent third-party attestation of the provider's security controls over a defined operating period, offering much stronger assurance than self-reported documentation.
In enterprise security architecture, what is the purpose of a Security Reference Architecture (SRA)?
Answer: To provide a reusable, standardized template of security controls and design patterns that align with business objectives and risk tolerance
A Security Reference Architecture provides standardized, reusable security design patterns and control blueprints that guide consistent security implementation across the enterprise aligned to business goals.
What security architectural pattern does a Content Delivery Network (CDN) with DDoS mitigation capability primarily implement?
Answer: Distributed traffic absorption and scrubbing that protects origin servers by dispersing attack traffic across global points of presence
CDNs with DDoS mitigation absorb and filter attack traffic at globally distributed edge nodes, preventing volumetric attacks from overwhelming origin infrastructure.
A CISO is designing security architecture for a DevSecOps pipeline. At which stage should static application security testing (SAST) be integrated for MAXIMUM effectiveness?
Answer: During the coding/build phase, so vulnerabilities are detected and remediated before they progress through the pipeline
Integrating SAST during the coding and build phases follows the 'shift left' principle, detecting vulnerabilities at the cheapest point in the SDLC before they propagate to later, more expensive stages.
Which architectural design decision BEST protects against cryptographic algorithm obsolescence (cryptographic agility)?
Answer: Designing systems to abstract cryptographic functions so algorithms can be swapped without major code changes
Cryptographic agility means designing systems so cryptographic primitives are abstracted and configurable, allowing organizations to update algorithms as standards evolve or vulnerabilities are discovered without application redesign.
When evaluating a security architecture against the NIST Cybersecurity Framework (CSF), which core function focuses on implementing appropriate safeguards to ensure delivery of critical infrastructure services?
Answer: Protect
The 'Protect' function of the NIST CSF focuses on developing and implementing appropriate safeguards to limit or contain the impact of a potential cybersecurity event.