Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Examen

CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT | COMPLETE EXAM 2026/2027 | QUESTIONS AND 100% VERIFIED ANSWERS NEWEST VERSION

Puntuación
-
Vendido
-
Páginas
40
Grado
A+
Subido en
15-07-2026
Escrito en
2025/2026

CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT | COMPLETE EXAM 2026/2027 | QUESTIONS AND 100% VERIFIED ANSWERS NEWEST VERSION

Institución
CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT
Grado
CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT

Vista previa del contenido

CNDA – Certified Network Defense Architect




CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT | COMPLETE EXAM 2026/2027 |
QUESTIONS AND 100% VERIFIED ANSWERS NEWEST VERSION


.

1. What is the primary goal of defense-in-depth architecture?
A. Layer multiple security controls so no single failure compromises
the network
B. Reduce the number of firewalls required
C. Eliminate the need for endpoint security
D. Centralize all security functions on one device
2. Which security model assumes no implicit trust for any user or
device, regardless of network location?
A. Castle-and-moat model
B. Zero Trust
C. Perimeter-based security
D. Implicit trust model
3. In the CIA triad, which principle ensures information is accurate and
unaltered?
A. Non-repudiation
B. Availability
C. Confidentiality
D. Integrity
4. What is the purpose of network segmentation in a defense
architecture?
A. Limit lateral movement by isolating network zones
B. Reduce the number of IP addresses needed
C. Eliminate the need for VLANs
D. Increase overall network bandwidth
5. Which term describes the sum of all points where an attacker could
attempt to enter a system?


Page 1 of 40

, CNDA – Certified Network Defense Architect



A. Kill chain
B. Threat vector
C. Attack tree
D. Attack surface
6. What does the principle of least privilege state?
A. Access should be granted based on seniority
B. All users should have administrative access by default
C. Users and systems should have only the access necessary to
perform their function
D. Privileges should never be revoked
7. Which document defines an organization's high-level approach to
protecting network assets?
A. Asset inventory
B. Security policy
C. Network diagram
D. Incident response runbook
8. A DMZ is primarily used to:
A. Host publicly accessible services while isolating them from the
internal network
B. Store encrypted backups
C. Replace the need for a firewall
D. Provide guest wireless access only
9. What is the main function of a security architecture review board?
A. Evaluate and approve changes to network defense architecture
for risk alignment
B. Manage employee onboarding
C. Perform daily log monitoring
D. Configure individual firewall rules
10. Which concept refers to designing systems assuming a breach has
already occurred?
A. Assume breach mindset
B. Air gapping
C. Security through obscurity

Page 2 of 40

, CNDA – Certified Network Defense Architect



D. Perimeter defense
11. What is the primary benefit of micro-segmentation compared to
traditional VLAN segmentation?
A. Elimination of encryption requirements
B. Lower hardware cost
C. Simplified routing tables
D. Granular, workload-level policy enforcement independent of
network topology
12. Which of the following best describes a security control baseline?
A. A schedule for patch deployment
B. A record of failed login attempts
C. A list of all open network ports
D. A minimum set of security controls required for a system based
on its risk category
13. What is the role of a Network Defense Architect in the SOC lifecycle?
A. Performing daily malware signature updates
B. Designing resilient network structures that support detection and
response capabilities
C. Managing the physical security guards
D. Approving budget for office supplies
14. Which term describes accepting a known risk without additional
mitigation because the cost of mitigation exceeds the potential loss?
A. Risk transfer
B. Risk avoidance
C. Risk mitigation
D. Risk acceptance
15. What is the purpose of a threat model in network defense design?
A. Calculate bandwidth requirements
B. Replace penetration testing
C. Document hardware inventory
D. Identify potential adversaries, their capabilities, and likely attack
paths



Page 3 of 40

, CNDA – Certified Network Defense Architect



16. Which architecture principle ensures that a single compromised
component cannot take down the entire network?
A. Resilience through redundancy and isolation
B. Flat network topology
C. Shared credential usage
D. Single point of failure design
17. What does 'security by design' mean in network architecture?
A. Adding security controls only after deployment
B. Relying solely on perimeter firewalls
C. Outsourcing all security decisions to vendors
D. Incorporating security requirements from the earliest stages of
system design
18. Which framework provides a structured set of network security
controls widely referenced by architects?
A. ITIL v3
B. Agile Manifesto
C. Six Sigma
D. NIST Cybersecurity Framework
19. What is an attack tree used for in network defense architecture?
A. Visually modeling how an attacker could achieve a specific goal
through various paths
B. Displaying network bandwidth utilization
C. Scheduling patch windows
D. Mapping physical cable layouts
20. Which term best describes redundant network paths designed to
maintain availability during a component failure?
A. Single homing
B. High availability design
C. Manual failover
D. Static routing only
21. What is the primary purpose of a network security baseline
configuration?
A. Increase device processing speed

Page 4 of 40

Escuela, estudio y materia

Institución
CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT
Grado
CNDA – CERTIFIED NETWORK DEFENSE ARCHITECT

Información del documento

Subido en
15 de julio de 2026
Número de páginas
40
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

$22.49
Accede al documento completo:

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Mirror Liberty University
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
427
Miembro desde
3 año
Número de seguidores
137
Documentos
5102
Última venta
1 día hace

3.8

61 reseñas

5
23
4
18
3
9
2
4
1
7

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes