Architecture Engineering OA
2026/2027 – Practice
Questions, Answers & Detailed
Rationales Guaranteed Pass
(GRADED A+)
Question 1
An organization wants to ensure that compromising one security
control does not expose its entire enterprise environment. Which
security architecture principle BEST supports this requirement?
A. Least privilege
B. Defense in depth
C. Separation of duties
D. Economy of mechanism
Answer: B. Defense in depth
Rationale: Defense in depth uses multiple complementary layers
of security controls. If one control fails or is bypassed,
additional controls can continue to protect systems,
applications, and data.
,Question 2
A company is implementing Zero Trust Architecture. Which
approach BEST aligns with the fundamental Zero Trust
principle?
A. Trust devices located inside the corporate network
B. Authenticate users only when they connect remotely
C. Continuously verify users, devices, and access requests
D. Allow unrestricted access after the initial login
_Answer: C. Continuously verify users, devices, and access
requests
Rationale: Zero Trust removes implicit trust based on network
location. Access decisions should consider identity, device
posture, resource, context, and other relevant signals rather
than assuming that an authenticated internal user is
automatically trustworthy.
Question 3
A security architect needs to isolate a finance department from
other departments while continuing to use the same physical
switching infrastructure. Which technology should be
implemented?
A. VLAN
B. NAT
C. DNS
D. SMTP
,_Answer: A. VLAN
Rationale: A Virtual Local Area Network logically separates
Layer 2 network segments. VLANs can isolate departmental
traffic without requiring separate physical switching
infrastructure.
Question 4
A publicly accessible web application is repeatedly receiving
malicious SQL injection requests. Which security control is
specifically designed to inspect and filter HTTP/HTTPS
application-layer traffic?
A. VPN concentrator
B. Web application firewall
C. Network hub
D. File integrity monitor
_Answer: B. Web application firewall
Rationale: A Web Application Firewall (WAF) protects web
applications by inspecting HTTP/HTTPS requests and can
detect or block attacks such as SQL injection and cross-site
scripting.
Question 5
, A company wants employees to access only the files and
applications required for their assigned responsibilities. Which
principle should guide the access-control design?
A. Least privilege
B. Open access
C. Implicit trust
D. Maximum availability
_Answer: A. Least privilege
Rationale: Least privilege grants users and processes only the
permissions necessary to perform their authorized tasks. This
limits the potential impact of compromised accounts or
processes.
Question 6
A security architect is designing an application that must
continue operating safely when a security-related failure occurs.
Which principle requires the system to default to a secure state
when access decisions cannot be completed?
A. Fail open
B. Fail secure
C. Single sign-on
D. Nonrepudiation
_Answer: B. Fail secure
Rationale: Fail-secure design causes a system to deny access or
otherwise maintain a protected state when an error or security-