Domain 3.0 — Security Architecture¶
← Back to Security+ overview · Domain weight: 18%
Q052. DMZ placement¶
A public web server must be reachable from the internet but should not sit directly inside the internal LAN. Where should it usually be placed?
- A. DMZ
- B. Management VLAN
- C. Backup network
- D. Domain controller subnet
Answer: A — DMZ
Why: A DMZ exposes public-facing services while limiting direct access to internal networks.
Q053. Jump server¶
Administrators need controlled access to production Linux servers from a restricted management network. Which architecture component best fits?
- A. Jump server / bastion host
- B. Open guest Wi-Fi
- C. Public NAT gateway only
- D. Honeypot
Answer: A — Jump server / bastion host
Why: A jump server centralizes and controls administrative access into sensitive environments.
Q054. Microsegmentation¶
A company wants workload-to-workload access rules in a data center so each application tier can only talk to approved services. What design is this?
- A. Microsegmentation
- B. Port mirroring
- C. Split tunneling
- D. DNS round robin
Answer: A — Microsegmentation
Why: Microsegmentation applies granular segmentation at the workload/application level.
Q055. NAC¶
Only corporate-managed laptops with current patches should connect to the wired network. Which solution is most appropriate?
- A. Network access control
- B. DNSSEC
- C. Honeynet
- D. Static NAT
Answer: A — Network access control
Why: NAC evaluates device/user posture before granting network access.
Q056. WAF¶
A company wants to block common web attacks such as SQL injection and XSS before they reach the application. What should be deployed?
- A. Web application firewall
- B. Layer 2 switch
- C. SNMP trap receiver
- D. RADIUS server
Answer: A — Web application firewall
Why: A WAF inspects HTTP/S application traffic and can block common web-application attacks.
Q057. CASB¶
A security team needs visibility and policy enforcement for users accessing SaaS applications. Which tool category is designed for this?
- A. CASB
- B. UPS
- C. HSM
- D. TPM
Answer: A — Cloud access security broker
Why: CASBs sit between users and cloud services or integrate via APIs to enforce cloud access/security policy.
Q058. SASE¶
A distributed company wants cloud-delivered network security and WAN capabilities closer to remote users. Which architecture best matches?
- A. SASE
- B. RAID 0
- C. Legacy hub-only VPN
- D. Cold site
Answer: A — Secure Access Service Edge
Why: SASE combines networking and security functions delivered as cloud services.
Q059. TLS inspection concern¶
A company decrypts outbound HTTPS traffic for inspection. What must be carefully managed to avoid breaking trust and privacy requirements?
- A. Enterprise CA certificates and policy scope
- B. DHCP lease duration
- C. Default gateway MAC address
- D. Screen resolution
Answer: A — Enterprise CA certificates and policy scope
Why: TLS inspection usually requires trusted enterprise certificates and careful handling of privacy, legal, and sensitive-data exceptions.
Q060. Data tokenization¶
A payment system replaces credit card numbers with non-sensitive surrogate values while storing the real numbers in a secure vault. What is this?
- A. Tokenization
- B. Hash collision
- C. Compression
- D. Steganography
Answer: A — Tokenization
Why: Tokenization substitutes sensitive data with tokens that are useless without the token vault/system.
Q061. Data masking¶
A support representative sees only the last four digits of a customer's SSN. What control is this?
- A. Data masking
- B. Full-disk encryption
- C. Hashing
- D. Salting
Answer: A — Data masking
Why: Masking hides part of the data from users who do not need the full value.
Q062. Data classification¶
A document is labeled "Confidential" and handling rules require encryption and restricted sharing. What process is being used?
- A. Data classification
- B. Port security
- C. Packet shaping
- D. Threat emulation
Answer: A — Data classification
Why: Classification assigns sensitivity labels that drive handling requirements.
Q063. Data sovereignty¶
A company must keep customer records in Germany due to legal requirements. What issue is this?
- A. Data sovereignty
- B. Data deduplication
- C. Data remanence only
- D. Federation
Answer: A — Data sovereignty
Why: Data sovereignty concerns which country's laws and jurisdiction apply to stored/processed data.
Q064. Resiliency: RTO¶
A business impact analysis says payroll must be restored within four hours after an outage. What metric is this?
- A. RTO
- B. RPO
- C. MTBF
- D. MTTR only
Answer: A — Recovery Time Objective
Why: RTO is the target time to restore service after disruption.
Q065. Resiliency: RPO¶
A database backup plan allows no more than 15 minutes of data loss. What metric is this?
- A. RPO
- B. RTO
- C. MTBF
- D. ALE
Answer: A — Recovery Point Objective
Why: RPO is the maximum acceptable amount of data loss measured in time.
Q066. High availability¶
Two firewalls operate as an active/passive pair. If the active device fails, the passive device takes over. What is the main goal?
- A. High availability
- B. Tokenization
- C. Obfuscation
- D. Non-repudiation
Answer: A — High availability
Why: Redundant components reduce downtime when one component fails.
Q067. RAID limitation¶
A server uses RAID 1. Which statement is most accurate?
- A. RAID helps availability but does not replace backups
- B. RAID prevents malware infection
- C. RAID encrypts disks
- D. RAID removes the need for patching
Answer: A — RAID helps availability but does not replace backups
Why: RAID can survive some disk failures but does not protect against deletion, corruption, ransomware, or site loss.
Q068. Immutable backup¶
A company wants backups that ransomware cannot alter or delete during the retention period. What feature best fits?
- A. Immutable backup storage
- B. DNS forwarding
- C. Password spraying
- D. Open guest network
Answer: A — Immutable backup storage
Why: Immutable backups are write-once/locked for a period, reducing the chance attackers can destroy recovery points.
Q069. Secure boot¶
A system validates bootloader signatures before loading the operating system. What is being used?
- A. Secure boot
- B. Port knocking
- C. Honeynet
- D. Kerberoasting
Answer: A — Secure boot
Why: Secure boot verifies trusted boot components to reduce bootkit/rootkit risk.
Q070. TPM¶
A laptop stores disk-encryption keys in hardware designed to protect secrets and measure boot state. What component is this?
- A. TPM
- B. WAF
- C. SIEM
- D. Proxy
Answer: A — Trusted Platform Module
Why: A TPM provides hardware-backed key storage and platform integrity measurements.
Q071. HSM¶
A certificate authority wants dedicated hardware to generate and protect private keys. What should it use?
- A. HSM
- B. IDS
- C. Fuzzer
- D. NAC
Answer: A — Hardware security module
Why: HSMs protect cryptographic keys and perform crypto operations in tamper-resistant hardware.
Q072. Container security boundary¶
Which statement about containers is most accurate for Security+ purposes?
- A. Containers share the host kernel and require hardening of images, runtime, and host
- B. Containers are always stronger isolation than VMs
- C. Containers eliminate patch management
- D. Containers cannot contain secrets
Answer: A — Containers share the host kernel and require hardening of images, runtime, and host
Why: Containers are isolated processes, not full hardware virtual machines. Image scanning, least privilege, and runtime controls matter.
Q073. Serverless security¶
Which risk remains important in serverless architectures?
- A. Insecure code and excessive function permissions
- B. Hypervisor patching by the customer
- C. Replacing IAM with VLANs
- D. Physical rack locks by the developer
Answer: A — Insecure code and excessive function permissions
Why: The provider manages much infrastructure, but customers still own code, identity permissions, secrets, and data handling.
Q074. Shared responsibility¶
In a public cloud IaaS VM deployment, which responsibility usually remains with the customer?
- A. Guest OS patching and application configuration
- B. Physical data-center guards
- C. Hypervisor hardware replacement
- D. Building power redundancy
Answer: A — Guest OS patching and application configuration
Why: In IaaS, the provider handles facilities and underlying infrastructure; the customer handles the guest OS, apps, identities, and data.
Q075. IaC security¶
A Terraform repository accidentally exposes cloud access keys. Which control would best prevent this from reaching production?
- A. Secret scanning in CI/CD
- B. Disable source control
- C. Use only screenshots for code review
- D. Increase DNS TTL
Answer: A — Secret scanning in CI/CD
Why: Automated scanning can detect committed secrets before deployment or before merge.
Q076. Secure baseline¶
A team deploys servers from a hardened image with approved settings and agents already installed. What concept is this?
- A. Secure baseline
- B. Hot site
- C. Watering hole
- D. Risk transference
Answer: A — Secure baseline
Why: A baseline defines approved secure configuration for consistent deployment.
Q077. Network segmentation for PCI¶
Cardholder data systems are isolated from general corporate workstations with strict firewall rules. What is the main security benefit?
- A. Reduced attack surface and compliance scope
- B. Faster DNS lookups
- C. Stronger password hashing
- D. Higher Wi-Fi signal strength
Answer: A — Reduced attack surface and compliance scope
Why: Segmentation limits access paths and may reduce systems in scope for regulatory controls.
Q078. Wireless security¶
Which wireless security mode is generally preferred for modern enterprise authentication?
- A. WPA3-Enterprise with 802.1X
- B. WEP
- C. Open Wi-Fi with hidden SSID
- D. WPA with TKIP
Answer: A — WPA3-Enterprise with 802.1X
Why: WPA3-Enterprise and 802.1X provide stronger modern enterprise authentication and encryption than legacy options.
Q173. Security group versus NACL¶
In a typical cloud VPC design, which statement is correct?
- A. Security groups are commonly stateful; network ACLs are commonly stateless
- B. Security groups are always physical firewalls
- C. NACLs authenticate users
- D. Security groups replace IAM
Answer: A — Security groups are commonly stateful; network ACLs are commonly stateless
Why: Many cloud platforms use stateful security groups and stateless subnet/network ACLs. Exact terms vary by provider, but the distinction is common exam material.
Q174. Private service endpoint¶
A database should be reachable from workloads inside a VPC without crossing the public internet. What architecture is most appropriate?
- A. Private endpoint/VPC endpoint/private link
- B. Public IP with any-any firewall
- C. Email attachment
- D. Guest Wi-Fi
Answer: A — Private endpoint/VPC endpoint/private link
Why: Private endpoints expose provider services through private addressing/routing and reduce public exposure.
Q175. IMDSv2 SSRF mitigation¶
A cloud VM role credential was stolen through SSRF against the instance metadata service. Which design improvement best reduces recurrence?
- A. Require session-oriented metadata access such as IMDSv2 and restrict metadata access where possible
- B. Open metadata service to the internet
- C. Store static keys in source code
- D. Disable TLS on the app
Answer: A — Require session-oriented metadata access such as IMDSv2 and restrict metadata access where possible
Why: Session-token metadata protections and network controls reduce metadata theft from SSRF, though application-side SSRF fixes are still required. (This is the exact class of attack behind the 2019 Capital One breach — see Q034 in Domain 2 for the underlying SSRF mechanism.)
Q176. Envelope encryption¶
A storage system encrypts each file with a data key, then encrypts that data key with a KMS key. What pattern is this?
- A. Envelope encryption
- B. DNSSEC
- C. Steganography
- D. Port knocking
Answer: A — Envelope encryption
Why: Envelope encryption protects large data with data encryption keys and protects those keys with a key-encryption key in KMS/HSM.
Q177. Customer-managed key tradeoff¶
A company chooses customer-managed cloud KMS keys instead of provider-managed keys. What responsibility increases?
- A. Key policy, rotation, access control, and lifecycle management
- B. Physical CPU manufacturing
- C. Internet BGP routing
- D. Browser rendering
Answer: A — Key policy, rotation, access control, and lifecycle management
Why: Customer-managed keys give more control but require more governance over access, rotation, deletion, and audit.
Q178. Secrets rotation¶
What is the best reason to use a secrets manager instead of storing credentials in environment-specific wiki pages?
- A. Centralized storage, access control, audit, and rotation support
- B. It makes passwords public
- C. It disables MFA
- D. It prevents all vulnerabilities
Answer: A — Centralized storage, access control, audit, and rotation support
Why: Secrets managers reduce sprawl and support controlled retrieval, auditing, expiration, and automated rotation.
Q179. Service mesh mTLS¶
A Kubernetes platform team wants workload-to-workload encryption and identity without changing every application. What design can help?
- A. Service mesh with mTLS sidecars or ambient dataplane
- B. Public S3 bucket
- C. Flat VLAN
- D. SMTP relay
Answer: A — Service mesh with mTLS sidecars or ambient dataplane
Why: Service meshes commonly provide workload identity, mTLS, and traffic policy outside application code.
Q180. API gateway control¶
Which function is most appropriate for an API gateway?
- A. Central JWT validation, rate limiting, routing, and request policy enforcement
- B. Replacing all database backups
- C. Generating user passwords manually
- D. Formatting laptops
Answer: A — Central JWT validation, rate limiting, routing, and request policy enforcement
Why: API gateways enforce common ingress controls such as auth, rate limits, request size limits, and routing.
Q181. CSPM versus CWPP¶
Which pairing is most accurate?
- A. CSPM checks cloud configuration posture; CWPP protects workloads such as VMs, containers, and serverless
- B. CSPM is a password hash; CWPP is a Wi-Fi protocol
- C. CSPM only works on printers
- D. CWPP replaces all network logging
Answer: A — CSPM checks cloud configuration posture; CWPP protects workloads such as VMs, containers, and serverless
Why: CSPM focuses on cloud control-plane posture and misconfiguration. CWPP focuses on workload protection.
Q182. Rootless containers¶
What is the main security benefit of rootless containers?
- A. Container root is not host root, reducing impact of some runtime/container escape paths
- B. They cannot have vulnerabilities
- C. They automatically encrypt all data
- D. They eliminate the kernel attack surface
Answer: A — Container root is not host root, reducing impact of some runtime/container escape paths
Why: Rootless mode maps privileges so UID 0 inside the container lacks equivalent host root privileges. It helps but does not make containers a security boundary by magic.
Q183. Linux capabilities¶
A container only needs to bind to low ports but not administer the host. Which principle applies?
- A. Drop all Linux capabilities except the minimum required capability
- B. Run privileged because it is simpler
- C. Mount the host root filesystem read-write
- D. Disable namespaces
Answer: A — Drop all Linux capabilities except the minimum required capability
Why: Linux capabilities split root privileges into smaller units. Dropping unnecessary capabilities enforces least privilege.
Q184. seccomp/AppArmor/SELinux¶
What is the purpose of controls such as seccomp, AppArmor, and SELinux in container or Linux hardening?
- A. Restrict system calls, file/resource access, and process behavior beyond basic UID permissions
- B. Speed up DNS lookups only
- C. Replace TLS certificates
- D. Create backups
Answer: A — Restrict system calls, file/resource access, and process behavior beyond basic UID permissions
Why: These controls reduce what a process can do even if compromised, limiting syscall and filesystem/resource access.
Q185. Kubernetes admission control¶
A cluster rejects pods that request privileged mode or use unapproved registries before they are created. What mechanism is involved?
- A. Admission controller/policy engine
- B. ARP cache
- C. MX record
- D. DHCP lease
Answer: A — Admission controller/policy engine
Why: Admission control evaluates Kubernetes API requests and can enforce security policy before objects are persisted.
Q186. Kubernetes network policy¶
A namespace should deny all pod-to-pod traffic unless explicitly allowed. What is the appropriate Kubernetes control?
- A. Default-deny NetworkPolicy plus explicit allow rules
- B. A ConfigMap with comments
- C. A larger node pool
- D. A public LoadBalancer for every pod
Answer: A — Default-deny NetworkPolicy plus explicit allow rules
Why: NetworkPolicy can implement default deny and specific ingress/egress rules if the CNI plugin enforces it.
Q187. Image signing¶
A production cluster should only deploy images built by the trusted CI pipeline. Which control best enforces this?
- A. Signed images with admission policy verifying signatures/provenance
- B. Manual screenshot approval
- C. Allowing latest tags only
- D. Disabling registry authentication
Answer: A — Signed images with admission policy verifying signatures/provenance
Why: Image signing and provenance verification help ensure the artifact came from a trusted build path and was not modified.
Q188. Immutable infrastructure¶
A team replaces servers by deploying new images instead of patching long-lived hosts in place. What design principle is this?
- A. Immutable infrastructure
- B. War dialing
- C. Open relay
- D. Rainbow table
Answer: A — Immutable infrastructure
Why: Immutable infrastructure reduces configuration drift and makes deployments reproducible. Existing instances are replaced rather than mutated.
Q189. Canary deployment for security patch¶
A critical patch may break production. Which rollout limits blast radius while providing early signal?
- A. Canary deployment to a small monitored subset before broader rollout
- B. Disable monitoring
- C. Patch all systems with no rollback plan
- D. Copy production data to a public bucket
Answer: A — Canary deployment to a small monitored subset before broader rollout
Why: Canary releases expose a limited subset first, reducing blast radius while measuring errors and security outcomes.
Q190. Offline root CA¶
Why keep a root CA offline and use intermediate CAs for issuing certificates?
- A. To protect the highest-trust key and limit day-to-day exposure
- B. To make certificates never expire
- C. To disable revocation
- D. To avoid identity validation
Answer: A — To protect the highest-trust key and limit day-to-day exposure
Why: Offline root CA design reduces likelihood of root key compromise. Intermediates perform operational issuance and can be revoked/replaced.
Q191. Secret zero problem¶
An app needs a secret to authenticate to the secrets manager. What is this bootstrapping issue called?
- A. Secret zero problem
- B. Rogue DHCP
- C. Hash collision
- D. VLAN hopping
Answer: A — Secret zero problem
Why: Secret zero is the initial credential or trust bootstrap needed to retrieve other secrets. Workload identity, instance identity, or hardware roots of trust can reduce static secret use.
Q192. Egress filtering value¶
Why is outbound filtering important if inbound firewalls are already strict?
- A. It can block command-and-control, data exfiltration, and unexpected cloud metadata/API access
- B. It makes phishing impossible
- C. It replaces patching
- D. It disables encryption
Answer: A — It can block command-and-control, data exfiltration, and unexpected cloud metadata/API access
Why: Compromised systems often initiate outbound connections. Egress policy limits attacker communication paths.
Q193. Object lock/WORM¶
A backup bucket must resist ransomware deletion and support compliance retention. Which feature is most relevant?
- A. Object lock/WORM immutability with retention policy
- B. Public read access
- C. Shorter passwords
- D. Single availability zone only
Answer: A — Object lock/WORM immutability with retention policy
Why: WORM/immutable storage prevents alteration or deletion for a retention period, improving resilience against malicious deletion.
Q194. Cloud audit log integrity¶
What design best protects cloud audit logs from a compromised admin in the production account?
- A. Send logs to a separate security account with restricted write-once storage and alerts on logging changes
- B. Store logs only on each compromised VM
- C. Let all admins delete logs
- D. Disable logs to reduce noise
Answer: A — Send logs to a separate security account with restricted write-once storage and alerts on logging changes
Why: Centralized logging into a separate account with restricted permissions helps preserve evidence and detect tampering.
Q195. Data residency design¶
A system must keep EU customer records in EU regions while allowing global analytics on aggregates. Which design is strongest?
- A. Regional data stores with residency controls and de-identified aggregate export
- B. One unrestricted global bucket
- C. Email raw records to analysts
- D. Disable classification
Answer: A — Regional data stores with residency controls and de-identified aggregate export
Why: Residency requirements are met by controlling storage/processing locations and minimizing exported identifiable data.
Q196. Zero trust policy decision¶
In zero trust, what should happen before each session to an enterprise resource is established?
- A. Authenticate and authorize subject and device using current context
- B. Trust the user because they are on the office LAN
- C. Bypass policy after first login forever
- D. Disable logging for internal traffic
Answer: A — Authenticate and authorize subject and device using current context
Why: Zero trust rejects implicit trust based on network location. Access decisions evaluate identity, device, and context before resource access. (Complements Q008 in Domain 1, which covers the broader zero-trust concept — this question tests the specific NIST SP 800-207 per-session enforcement model.)
Q197. Thin client data reduction¶
A contractor needs access to sensitive apps but should not store data locally. Which architecture helps most?
- A. VDI/DaaS with clipboard/download restrictions and monitored session controls
- B. Local admin on unmanaged laptop
- C. Public file share
- D. Email export of the database
Answer: A — VDI/DaaS with clipboard/download restrictions and monitored session controls
Why: Virtual desktops can centralize data and restrict local copy paths, though they still require identity, endpoint, and monitoring controls.
← Domain 2 · Back to Security+ overview · Next: Domain 4 — Security Operations →