CEA CEA - Certified Enterprise Architect EA Risk and Security Architecture Questions and Answers 1 — Questions and Answers
Question 1: Which enterprise architecture layer is PRIMARILY responsible for defining security policies, access controls, and identity management requirements?
- Application Architecture
- Data Architecture
- Security Architecture within the Technology Architecture domain (Correct answer)
- Business Architecture
Correct answer: Security Architecture within the Technology Architecture domain
Security architecture within the Technology Architecture domain defines security policies, identity management, and access control frameworks.
Question 2: What is the PRIMARY purpose of a threat modeling exercise in enterprise architecture?
- To estimate project costs
- To identify potential security threats, vulnerabilities, and corresponding mitigation strategies across the architecture (Correct answer)
- To create network diagrams
- To define software development standards
Correct answer: To identify potential security threats, vulnerabilities, and corresponding mitigation strategies across the architecture
Threat modeling systematically identifies security threats and vulnerabilities so that mitigations can be designed into the architecture.
Question 3: Which NIST framework is MOST commonly referenced when building a security architecture in US federal or enterprise environments?
- NIST SP 800-53 (Security and Privacy Controls) (Correct answer)
- NIST SP 500-292 (Cloud Computing Reference Architecture)
- NIST SP 800-145 (Cloud Computing Definition)
- NIST SP 800-61 (Incident Handling Guide)
Correct answer: NIST SP 800-53 (Security and Privacy Controls)
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls widely used in US federal and enterprise security architectures.
Question 4: In enterprise architecture, what does the term 'defense in depth' mean?
- Using a single strong firewall to protect all systems
- Layering multiple security controls so that if one fails, others continue to protect the asset (Correct answer)
- Focusing security resources on the most critical application only
- Encrypting all data at rest
Correct answer: Layering multiple security controls so that if one fails, others continue to protect the asset
Defense in depth applies multiple, overlapping security controls across different layers so that no single point of failure compromises the entire system.
Question 5: An enterprise architect is designing a cloud migration strategy. Which security principle requires that each component only has access to the resources it needs?
- Separation of duties
- Principle of least privilege (Correct answer)
- Defense in depth
- Non-repudiation
Correct answer: Principle of least privilege
The principle of least privilege ensures components and users have only the minimum access required to perform their function, reducing the attack surface.
Question 6: What is an Architecture Risk Register used for in enterprise architecture practice?
- Tracking employee vacation schedules
- Documenting identified architectural risks, their likelihood, impact, and mitigation actions (Correct answer)
- Managing vendor invoice payments
- Recording software bug reports
Correct answer: Documenting identified architectural risks, their likelihood, impact, and mitigation actions
An Architecture Risk Register captures identified risks to the architecture, including probability, impact, and planned mitigations.
Which enterprise architecture layer is PRIMARILY responsible for defining security policies, access controls, and identity management requirements?