โ† All CCISO Flashcard Decks

Security Architecture Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Architecture flashcards as text
  1. In a hybrid cloud architecture, what is the MOST important architectural consideration for maintaining consistent security policies?

    Answer: Implementing a unified identity and access management (IAM) framework across on-premises and cloud environments

    A unified IAM framework ensures consistent identity verification, access controls, and policy enforcement across hybrid environments, preventing security gaps at integration points.

  2. What is the architectural difference between an Intrusion Detection System (IDS) and an Intrusion Prevention System (IPS) in terms of network placement?

    Answer: IDS is typically placed out-of-band (passive monitoring) while IPS is placed inline (active blocking)

    IDS is deployed out-of-band to passively monitor and alert on suspicious traffic, while IPS is deployed inline and can actively block malicious traffic in real time.

  3. A CISO must design an architecture to protect sensitive PII while allowing data analytics teams to work with the data. Which architectural approach BEST addresses this requirement?

    Answer: Implementing data masking or tokenization to provide de-identified data for analytics while protecting the original PII

    Data masking and tokenization allow organizations to replace sensitive PII with realistic but non-sensitive substitutes, enabling analytics work without exposing actual personal data.

  4. Which security architecture principle states that a subject should only have the minimum access rights necessary to perform its authorized functions?

    Answer: Least privilege

    The principle of least privilege limits user and system permissions to the minimum required to accomplish legitimate tasks, reducing the potential damage from errors, attacks, or compromised accounts.

  5. When designing a security architecture for a containerized environment, which control is MOST effective at preventing container escape attacks?

    Answer: Enforcing kernel namespace isolation and running containers with non-root user contexts and read-only file systems

    Container escape prevention relies on kernel namespace isolation, dropping unnecessary capabilities, running as non-root, and using read-only file systems to limit what an attacker can do even if they compromise a container.

  6. A financial institution's CISO is designing an architecture to detect insider threats. Which combination of controls provides the MOST comprehensive detection capability?

    Answer: User and Entity Behavior Analytics (UEBA) combined with Data Loss Prevention (DLP) and privileged access monitoring

    UEBA detects anomalous behavior patterns, DLP monitors and controls data movement, and privileged access monitoring tracks high-risk accounts, together providing comprehensive insider threat detection.

  7. In a Software-Defined Networking (SDN) architecture, what is the primary security concern introduced by centralizing network control in the SDN controller?

    Answer: The SDN controller becomes a high-value single point of attack that, if compromised, allows complete network manipulation

    The centralized SDN controller is a critical single point of failure and a high-value target; compromising it gives an attacker full control over network routing, segmentation, and traffic flows.