CSL CSL Security Architecture & Technology Leadership 1 — Questions and Answers
Question 1: As a cybersecurity leader, what is the primary goal of a Zero Trust architecture model?
- Eliminate all perimeter defenses entirely
- Never trust, always verify every user and device regardless of location (Correct answer)
- Grant broad access to authenticated users on the corporate network
- Replace all legacy systems with cloud-native solutions
Correct answer: Never trust, always verify every user and device regardless of location
Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous validation of every user, device, and connection.
Question 2: Which security architecture principle ensures that a compromised component cannot access resources beyond its defined scope?
- Defense in depth
- Least privilege (Correct answer)
- Security by obscurity
- Network segmentation
Correct answer: Least privilege
The principle of least privilege limits each component or user to only the access rights necessary for its specific function.
Question 3: A CISO is evaluating cloud security architecture. Which framework is most commonly used to assess cloud provider security controls?
- OWASP Top 10
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- NIST SP 800-53
- ISO 27001
Correct answer: CSA Cloud Controls Matrix (CCM)
The Cloud Security Alliance's Cloud Controls Matrix is specifically designed to assess security controls across cloud service providers.
Question 4: What is the key difference between a SIEM and a SOAR platform in enterprise security architecture?
- SIEM automates responses while SOAR aggregates log data
- SIEM collects and correlates data while SOAR automates incident response workflows (Correct answer)
- SIEM is cloud-only while SOAR is on-premises only
- SIEM handles endpoints while SOAR handles network traffic
Correct answer: SIEM collects and correlates data while SOAR automates incident response workflows
SIEM focuses on log aggregation and threat correlation, while SOAR adds automated playbook execution to accelerate incident response.
Question 5: When leading a technology selection process for endpoint detection and response (EDR), what criterion should take highest priority?
- Lowest total cost of ownership
- Integration capability with existing security stack (Correct answer)
- Vendor market share ranking
- Feature richness of the management console
Correct answer: Integration capability with existing security stack
Integration capability ensures the EDR solution can share telemetry and coordinate responses with existing SIEM, SOAR, and identity tools.
Question 6: Which architecture approach best supports a resilient security posture by assuming breaches will occur?
- Perimeter-based security model
- Assume breach / resilience-focused architecture (Correct answer)
- Air-gapped network design
- Security through obscurity model
Correct answer: Assume breach / resilience-focused architecture
The 'assume breach' mindset focuses on detection, containment, and recovery capabilities rather than solely on prevention.
As a cybersecurity leader, what is the primary goal of a Zero Trust architecture model?