CEA - Certified Enterprise Architect EA Risk and Security Architecture Questions and Answers Flashcards
6 cards from real CEA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CEA - Certified Enterprise Architect EA Risk and Security Architecture Questions and Answers flashcards as text
Which security architecture model divides an enterprise network into zones with increasing levels of trust and access control?
Answer: Zero-trust architecture with micro-segmentation
Zero-trust architecture with micro-segmentation divides networks into isolated zones, requiring verification for every access request regardless of location.
What is the relationship between enterprise architecture and Business Continuity Planning (BCP)?
Answer: EA provides the architectural foundation (redundancy, failover, recovery) that BCP relies on to meet RTO and RPO targets
EA defines the technical redundancy and failover patterns that Business Continuity Plans depend on to achieve recovery time and point objectives.
Which of the following is a key output of a security architecture review in the EA process?
Answer: Security risk assessment with identified gaps and recommended controls
A security architecture review produces a risk assessment identifying gaps between the current security posture and the required controls.
An enterprise architect is asked to evaluate a proposed SaaS vendor. Which security concern is MOST critical to assess?
Answer: Data residency, access controls, encryption standards, and compliance certifications (e.g., SOC 2, ISO 27001)
For SaaS evaluation, data residency, encryption, access controls, and compliance certifications directly determine whether the vendor meets enterprise security requirements.
What does 'non-repudiation' mean in the context of enterprise security architecture?
Answer: Providing proof that a specific party performed a specific action, preventing denial of that action
Non-repudiation ensures there is irrefutable evidence that a specific party performed an action, such as through digital signatures or audit logs.
Which risk treatment option involves transferring risk to a third party, such as through insurance or outsourcing?
Answer: Risk transfer
Risk transfer shifts the financial or operational impact of a risk to a third party, commonly through insurance policies or managed service agreements.