Architecture Assessment Study Guide Questions
Correctly Solved to Score A+
An organization plans to implement a load balancer as part of its network infrastructure to manage the
increased web traffic to its services. The organization tasks a network administrator with ensuring that
the load balancer configures in line with best security practices to reduce the attack surface and secure
the enterprise infrastructure. The network administrator's responsibilities include evaluating the
network appliances, securing connectivity, and considering device placement. What is th - Answer A.
Implement a Web Application Firewall alongside the load balancer.
A multinational corporation handles human-readable and non-human-readable data. What are the
implications for security operations and controls? - Answer A. Security measures for non-human-
readable data: encryption, access controls, intrusion detection/prevention, and secure data exchange
(incorrect)
B. Security measures for human-readable data: monitoring, user awareness, encryption, and secure data
exchange (incorrect)
The IT manager of a medium-sized organization is designing a new network infrastructure to secure its
enterprise infrastructure by implementing an Intrusion Prevention System (IPS) and an Intrusion
Detection System (IDS). The manager is considering different deployment methods for the IPS/IDS to
optimize their effectiveness. The organization's network includes multiple security zones, a virtual
private network (VPN) for remote access, and a web application firewall (WAF). Which deployment
method - Answer C. Deploy the IPS/IDS devices in inline mode at the network perimeter.
An IT specialist working for a multinational confectionery company needs to fortify its network security.
The firm has been dealing with intrusions where raw User Datagram Protocol (UDP) packets bypass
open ports due to a virus. The specialist will analyze packet data to verify that the application protocol
corresponds to the port. The company also wants to track the state of sessions and prevent fraudulent
session initiations. Which of the following tools should the IT specialist prioritize deploying? - Answer D.
Deep packet inspection firewall
A manufacturing firm is exploring the implementation of an isolated network system for its plant floor
operations. The goal is to prevent any unauthorized or accidental communication with other networks.
The firm plans to manage large-scale, real-time processes using this system. Which type of infrastructure
will BEST fit the firm's needs? - Answer D. ICS/SCADA infrastructure
, A medium-sized organization elects to redesign its network security infrastructure. The IT manager is
considering implementing a proxy server to enhance security and improve client performance. The
organization's network includes a virtual private network (VPN) for remote access, multiple security
zones, and a Unified Threat Management (UTM) system. Which of the following is the primary benefit of
implementing a proxy server in this scenario? - Answer B. The proxy server can perform application-
layer filtering, enhancing network traffic security.
A global e-commerce company faces challenges with its legacy monolithic application. The application is
becoming increasingly difficult to maintain due to its intertwined components and struggles to scale
quickly enough to handle sudden traffic surges during big sales events. The company has already
invested in cloud technology and on-premises infrastructure but still faces scalability and manageability
issues. What would MOST effectively address these challenges? - Answer A. Microservices
A large multinational corporation is restructuring its IT division. The corporation defines roles,
responsibilities, and levels of authority for different tasks across various teams. What type of tool is the
corporation likely to use to document this information? - Answer B. Responsibility matrix
The IT department of a healthcare provider maintains a database containing personal health
information for its patients. Which classification BEST suits this type of data? - Answer D. Regulated
A corporation is experiencing frequent power failures in its data center, which are causing downtime
and resulting in high recovery costs. Which strategy could the corporation employ to minimize the
impact of these power failures? - Answer D. Implement a UPS system
An organization wants to improve the security of sensitive customer information stored on its servers.
This sensitive customer information is "data at rest" and not currently accessed or processed. Which
method should the organization consider for protecting this data? - Answer C. Encryption
During an annual review, a health services company's leadership aims to scrutinize its disaster response
and data recovery protocols. They focus on effectiveness, hidden weaknesses, and clarity of employee
roles during a disaster. Which course of action would BEST serve these objectives? - Answer C.
Organizing tabletop exercises
A cloud administrator wants to directly connect a cloud server instance with another cloud server
instance privately on Amazon Web Services (AWS). How can the administrator configure them without
going through an internet gateway? - Answer B. By using a virtual private cloud (VPC) peering
connection