CSL CSL Security Architecture & Technology Management 2 — Questions and Answers
Question 1: Which technology management practice ensures security tools remain effective as the threat landscape evolves?
- Continuous vulnerability management and patch cycles (Correct answer)
- One-time security assessments
- Static firewall rule sets
- Annual technology refreshes only
Correct answer: Continuous vulnerability management and patch cycles
Continuous vulnerability management and regular patching ensure security tools and systems stay current against evolving threats.
Question 2: A CSL leader reviews a proposal for cloud migration. What security principle should guide data classification in the cloud?
- Data sensitivity determines required controls and residency requirements (Correct answer)
- All cloud data should be public by default
- Cloud providers handle all data security automatically
- Encryption is optional if using a reputable provider
Correct answer: Data sensitivity determines required controls and residency requirements
Data sensitivity classification drives the appropriate security controls, encryption requirements, and geographic data residency decisions in cloud environments.
Question 3: What is the purpose of a security technology roadmap in cybersecurity leadership?
- Align planned security tool investments to future business and threat requirements (Correct answer)
- List all currently installed security software
- Document past security incidents
- Replace the enterprise risk register
Correct answer: Align planned security tool investments to future business and threat requirements
A security technology roadmap provides a forward-looking plan that aligns security investments with anticipated business growth and emerging threats.
Question 4: Which architecture model treats every user and device as untrusted regardless of network location?
- Zero Trust Architecture (Correct answer)
- Perimeter-based security
- Air-gapped network model
- Open network model
Correct answer: Zero Trust Architecture
Zero Trust Architecture operates on 'never trust, always verify,' requiring continuous authentication regardless of whether a user is inside or outside the network perimeter.
Question 5: A cybersecurity leader is evaluating SIEM tools. What is the primary function of a SIEM in an enterprise?
- Aggregate and correlate security event logs for threat detection and response (Correct answer)
- Block malware at the endpoint
- Encrypt data in transit
- Manage user access credentials
Correct answer: Aggregate and correlate security event logs for threat detection and response
A SIEM (Security Information and Event Management) system collects, aggregates, and correlates logs from across the enterprise to detect and investigate security threats.
Question 6: Why should a CSL leader ensure security architecture reviews occur during mergers and acquisitions?
- Acquired systems may introduce unknown vulnerabilities and incompatible security controls (Correct answer)
- It is only required by SOX regulations
- Mergers automatically transfer security certifications
- Acquired companies always have stronger security
Correct answer: Acquired systems may introduce unknown vulnerabilities and incompatible security controls
M&A activity introduces inherited systems with potentially unknown security gaps that must be assessed before integration to avoid introducing new risks.
Which technology management practice ensures security tools remain effective as the threat landscape evolves?