CySA+ Test Security Architecture and Tools Flashcards
6 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CySA+ Test Security Architecture and Tools flashcards as text
Which security architecture principle ensures that users and systems are granted only the minimum permissions necessary to perform their functions?
Answer: Least privilege
The principle of least privilege limits access rights to only what is strictly required, reducing the attack surface if an account is compromised.
A CySA+ analyst is evaluating a network where every access request is verified regardless of whether the user is inside or outside the network perimeter. Which model is this?
Answer: Zero trust
Zero trust operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every access request.
Which security tool provides real-time analysis of security alerts generated by network hardware and applications?
Answer: SIEM
A SIEM (Security Information and Event Management) system aggregates and analyzes log data from multiple sources to detect threats in real time.
Which architecture concept involves placing publicly accessible servers in a network segment separated from the internal network?
Answer: DMZ (Demilitarized Zone)
A DMZ is a perimeter network that exposes external-facing services while shielding the internal network from direct external access.
Which tool is used to inspect and filter traffic at the application layer, providing deeper visibility than a traditional packet filter firewall?
Answer: Next-Generation Firewall (NGFW)
An NGFW performs deep packet inspection at the application layer, identifying and controlling applications regardless of port or protocol.
Which security design principle recommends using multiple overlapping security controls so that the failure of one does not compromise the entire system?
Answer: Defense in depth
Defense in depth layers multiple security controls so that if one layer fails, additional layers continue to protect assets.