CSL CSL Security Architecture & Technology Leadership 2 — Questions and Answers
Question 1: A cybersecurity leader is selecting between on-premises and cloud-based security solutions. Which factor most directly affects the risk profile of the decision?
- Vendor reputation in analyst reports
- Data residency and sovereignty requirements (Correct answer)
- Number of available integrations
- Support hours offered by the vendor
Correct answer: Data residency and sovereignty requirements
Data residency laws dictate where certain data can be stored and processed, directly affecting regulatory compliance and legal risk.
Question 2: What is the purpose of a security reference architecture in an enterprise context?
- To document all past security incidents
- To provide a blueprint for consistent, scalable security controls across the organization (Correct answer)
- To replace security policies with technical standards only
- To define the IT help desk escalation process
Correct answer: To provide a blueprint for consistent, scalable security controls across the organization
A security reference architecture establishes standardized patterns and controls that teams can replicate consistently across projects and platforms.
Question 3: Which encryption standard is currently recommended by NIST for protecting data in US federal environments?
- DES (Data Encryption Standard)
- AES-256 (Advanced Encryption Standard) (Correct answer)
- RC4 stream cipher
- MD5 hashing algorithm
Correct answer: AES-256 (Advanced Encryption Standard)
NIST recommends AES-256 as the current standard for symmetric encryption of sensitive and classified data.
Question 4: A security architect proposes micro-segmentation for the data center. What is the primary security benefit?
- Reduces hardware procurement costs
- Limits lateral movement of attackers within the network (Correct answer)
- Eliminates the need for firewalls
- Simplifies network management overhead
Correct answer: Limits lateral movement of attackers within the network
Micro-segmentation creates isolated zones that prevent attackers who gain initial access from moving freely across systems.
Question 5: Which PKI component is responsible for issuing and revoking digital certificates in an organization?
- Registration Authority (RA)
- Certificate Authority (CA) (Correct answer)
- Key Distribution Center (KDC)
- Directory Service (DS)
Correct answer: Certificate Authority (CA)
The Certificate Authority is the trusted entity that issues, signs, and revokes digital certificates within a PKI infrastructure.
Question 6: When evaluating security tools as a technology leader, what does 'defense in depth' require?
- Using a single best-of-breed security tool
- Deploying multiple overlapping layers of security controls (Correct answer)
- Focusing only on perimeter defenses
- Prioritizing detection over prevention
Correct answer: Deploying multiple overlapping layers of security controls
Defense in depth requires layering multiple independent security controls so that failure of one does not compromise the entire security posture.
A cybersecurity leader is selecting between on-premises and cloud-based security solutions.
Which factor most directly affects the risk profile of the decision?