CSL CSL Security Architecture & Technology Management 1 — Questions and Answers
Question 1: Which security architecture framework is widely used by US federal agencies and defines a zero trust model?
- NIST SP 800-207 (Correct answer)
- ISO 27001
- COBIT 5
- SABSA
Correct answer: NIST SP 800-207
NIST SP 800-207 is the federal standard defining zero trust architecture principles adopted across US government agencies.
Question 2: A cybersecurity leader wants to ensure security is integrated from the start of software development. Which approach best achieves this?
- Shift-left security (Correct answer)
- Penetration testing at release
- Firewall-only perimeter defense
- Post-deployment patching
Correct answer: Shift-left security
Shift-left security embeds security controls early in the development lifecycle, reducing vulnerabilities before they reach production.
Question 3: What is the primary purpose of a security reference architecture in an enterprise?
- Provide a reusable blueprint for consistent security design across systems (Correct answer)
- Document all known vulnerabilities
- Replace the need for security policies
- Track individual user behavior
Correct answer: Provide a reusable blueprint for consistent security design across systems
A security reference architecture provides standardized, reusable patterns that guide consistent security implementation across the enterprise.
Question 4: Which of the following best describes defense-in-depth as a security architecture principle?
- Multiple overlapping layers of security controls (Correct answer)
- One highly effective perimeter firewall
- Encrypting all data at rest only
- Relying solely on endpoint detection tools
Correct answer: Multiple overlapping layers of security controls
Defense-in-depth uses multiple overlapping security layers so that if one control fails, others still protect the asset.
Question 5: A CSL leader must evaluate technology investments for security. What framework helps align security technology to business capability gaps?
- SABSA (Sherwood Applied Business Security Architecture) (Correct answer)
- PCI DSS
- HIPAA
- SOC 2
Correct answer: SABSA (Sherwood Applied Business Security Architecture)
SABSA provides a business-driven framework for developing security architectures aligned to organizational capability requirements.
Question 6: What is the key security benefit of network segmentation in enterprise architecture?
- Limits lateral movement of attackers across systems (Correct answer)
- Eliminates the need for encryption
- Removes the need for firewalls
- Reduces software licensing costs
Correct answer: Limits lateral movement of attackers across systems
Network segmentation contains breaches by preventing attackers from moving freely across different network zones.
Which security architecture framework is widely used by US federal agencies and defines a zero trust model?