CompTIA Security+ SY0-701 Security Architecture Models Practice Test

 

Topic 10 focuses on Security Architecture Models for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which division of security duties between a cloud service provider and the customer varies by service model?

  1. Software-defined networking (SDN)
  2. Containerization
  3. Infrastructure as code (IaC)
  4. Cloud shared-responsibility model

Correct Answer: D

 

Correct Answer

Answer D is correct because Cloud shared-responsibility model means a division of security duties between a cloud service provider and the customer that varies by service model.

Incorrect Answers

Answer A is incorrect because Software-defined networking (SDN) would fit a different scenario. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer B is incorrect because Containerization addresses a different requirement. Containerization refers to operating-system-level isolation that packages applications and dependencies into lightweight containers.

Answer C is incorrect because Infrastructure as code (IaC) represents a different security function. Infrastructure as code (IaC) refers to definition and deployment of infrastructure through machine-readable configuration or code.

 

Question 2

To integrate security across different trust, ownership, and connectivity models, which security approach should be selected?

  1. Real-time operating system (RTOS)
  2. Hybrid architecture
  3. On-premises architecture
  4. Infrastructure as code (IaC)

Correct Answer: B

 

Correct Answer

Answer B is correct because Hybrid architecture means an environment combining on-premises resources with cloud or other externally hosted services.

Incorrect Answers

Answer A is incorrect because Real-time operating system (RTOS) addresses a different requirement. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

Answer C is incorrect because On-premises architecture addresses a different security requirement. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

Answer D is incorrect because Infrastructure as code (IaC) would fit a different scenario. Infrastructure as code (IaC) refers to definition and deployment of infrastructure through machine-readable configuration or code.

 

Question 3

Which term describes definition and deployment of infrastructure through machine-readable configuration or code?

  1. Serverless architecture
  2. Infrastructure as code (IaC)
  3. Decentralized architecture
  4. Software-defined networking (SDN)

Correct Answer: B

 

Correct Answer

Answer B is correct because Infrastructure as code (IaC) means definition and deployment of infrastructure through machine-readable configuration or code.

Incorrect Answers

Answer A is incorrect because Serverless architecture represents a different security function. Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Answer C is incorrect because Decentralized architecture would fit a different scenario. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

Answer D is incorrect because Software-defined networking (SDN) addresses a different requirement. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

 

Question 4

To run application logic without directly administering servers, which security approach should be selected?

  1. Serverless architecture
  2. Software-defined networking (SDN)
  3. Hybrid architecture
  4. Containerization

Correct Answer: A

 

Correct Answer

Answer A is correct because Serverless architecture means a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Incorrect Answers

Answer B is incorrect because Software-defined networking (SDN) addresses a different security requirement. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer C is incorrect because Hybrid architecture addresses a different requirement. Hybrid architecture refers to an environment combining on-premises resources with cloud or other externally hosted services.

Answer D is incorrect because Containerization would fit a different scenario. Containerization refers to operating-system-level isolation that packages applications and dependencies into lightweight containers.

 

Question 5

What is an application model composed of small independently deployable services communicating through defined interfaces?

  1. High availability
  2. Resilience
  3. Decentralized architecture
  4. Microservices architecture

Correct Answer: D

 

Correct Answer

Answer D is correct because Microservices architecture means an application model composed of small independently deployable services communicating through defined interfaces.

Incorrect Answers

Answer A is incorrect because High availability represents a different security function. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer B is incorrect because Resilience would fit a different scenario. Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation.

Answer C is incorrect because Decentralized architecture addresses a different requirement. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

 

Question 6

To reduce remote attack paths for highly sensitive systems, which security approach should be selected?

  1. ICS/SCADA
  2. Virtualization
  3. Centralized architecture
  4. Air-gapped network

Correct Answer: D

 

Correct Answer

Answer D is correct because Air-gapped network means a network intentionally isolated from other networks through physical separation.

Incorrect Answers

Answer A is incorrect because ICS/SCADA addresses a different security requirement. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

Answer B is incorrect because Virtualization would fit a different scenario. Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Answer C is incorrect because Centralized architecture addresses a different requirement. Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service.

 

Question 7

Which term describes separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation?

  1. Microservices architecture
  2. Logical segmentation
  3. Real-time operating system (RTOS)
  4. On-premises architecture

Correct Answer: B

 

Correct Answer

Answer B is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

Incorrect Answers

Answer A is incorrect because Microservices architecture would fit a different scenario. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

Answer C is incorrect because Real-time operating system (RTOS) represents a different security function. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

Answer D is incorrect because On-premises architecture addresses a different requirement. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

 

Question 8

To program network behavior and policy through centralized software control, which security approach should be selected?

  1. Software-defined networking (SDN)
  2. Real-time operating system (RTOS)
  3. Resilience
  4. Hybrid architecture

Correct Answer: A

 

Correct Answer

Answer A is correct because Software-defined networking (SDN) means a networking model that separates centralized control logic from packet-forwarding functions.

Incorrect Answers

Answer B is incorrect because Real-time operating system (RTOS) addresses a different security requirement. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

Answer C is incorrect because Resilience would fit a different scenario. Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation.

Answer D is incorrect because Hybrid architecture addresses a different requirement. Hybrid architecture refers to an environment combining on-premises resources with cloud or other externally hosted services.

 

Question 9

Which term describes systems operated in facilities and infrastructure controlled directly by the organization?

  1. High availability
  2. Software-defined networking (SDN)
  3. On-premises architecture
  4. Decentralized architecture

Correct Answer: C

 

Correct Answer

Answer C is correct because On-premises architecture means systems operated in facilities and infrastructure controlled directly by the organization.

Incorrect Answers

Answer A is incorrect because High availability represents a different security function. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer B is incorrect because Software-defined networking (SDN) would fit a different scenario. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer D is incorrect because Decentralized architecture addresses a different requirement. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

 

Question 10

To simplify governance and consistency at the cost of greater dependency on central components, which security approach should be selected?

  1. Centralized architecture
  2. Cloud shared-responsibility model
  3. Decentralized architecture
  4. Microservices architecture

Correct Answer: A

 

Correct Answer

Answer A is correct because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service.

Incorrect Answers

Answer B is incorrect because Cloud shared-responsibility model addresses a different requirement. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer C is incorrect because Decentralized architecture would fit a different scenario. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

Answer D is incorrect because Microservices architecture addresses a different security requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 11

Which design distributes control or processing across multiple independent components or locations?

  1. Virtualization
  2. Centralized architecture
  3. Decentralized architecture
  4. Real-time operating system (RTOS)

Correct Answer: C

 

Correct Answer

Answer C is correct because Decentralized architecture means a design that distributes control or processing across multiple independent components or locations.

Incorrect Answers

Answer A is incorrect because Virtualization would fit a different scenario. Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Answer B is incorrect because Centralized architecture addresses a different requirement. Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service.

Answer D is incorrect because Real-time operating system (RTOS) represents a different security function. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

 

Question 12

To deploy portable workloads with stronger process isolation than ordinary applications, which security approach should be selected?

  1. Containerization
  2. Software-defined networking (SDN)
  3. Cloud shared-responsibility model
  4. On-premises architecture

Correct Answer: A

 

Correct Answer

Answer A is correct because Containerization means operating-system-level isolation that packages applications and dependencies into lightweight containers.

Incorrect Answers

Answer B is incorrect because Software-defined networking (SDN) addresses a different security requirement. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer C is incorrect because Cloud shared-responsibility model would fit a different scenario. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer D is incorrect because On-premises architecture addresses a different requirement. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

 

Question 13

Which term describes abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor?

  1. Cloud shared-responsibility model
  2. Virtualization
  3. Microservices architecture
  4. High availability

Correct Answer: B

 

Correct Answer

Answer B is correct because Virtualization means abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Incorrect Answers

Answer A is incorrect because Cloud shared-responsibility model represents a different security function. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer C is incorrect because Microservices architecture addresses a different requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

Answer D is incorrect because High availability would fit a different scenario. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

 

Question 14

To secure nontraditional devices that may have limited patching and authentication capabilities, which security approach should be selected?

  1. Internet of Things (IoT)
  2. ICS/SCADA
  3. Scalability
  4. On-premises architecture

Correct Answer: A

 

Correct Answer

Answer A is correct because Internet of Things (IoT) means network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles.

Incorrect Answers

Answer B is incorrect because ICS/SCADA addresses a different security requirement. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

Answer C is incorrect because Scalability would fit a different scenario. Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources.

Answer D is incorrect because On-premises architecture addresses a different requirement. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

 

Question 15

Which term describes industrial control and supervisory systems used to monitor or control physical processes?

  1. Risk transference
  2. Software-defined networking (SDN)
  3. On-premises architecture
  4. ICS/SCADA

Correct Answer: D

 

Correct Answer

Answer D is correct because ICS/SCADA means industrial control and supervisory systems used to monitor or control physical processes.

Incorrect Answers

Answer A is incorrect because Risk transference represents a different security function. Risk transference refers to shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements.

Answer B is incorrect because Software-defined networking (SDN) would fit a different scenario. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer C is incorrect because On-premises architecture addresses a different requirement. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

 

Question 16

To support embedded or industrial workloads where predictable timing is critical, which security approach should be selected?

  1. High availability
  2. Resilience
  3. Real-time operating system (RTOS)
  4. ICS/SCADA

Correct Answer: C

 

Correct Answer

Answer C is correct because Real-time operating system (RTOS) means an operating system designed to meet strict timing and deterministic response requirements.

Incorrect Answers

Answer A is incorrect because High availability would fit a different scenario. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer B is incorrect because Resilience addresses a different requirement. Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation.

Answer D is incorrect because ICS/SCADA addresses a different security requirement. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

 

Question 17

Which term describes architecture designed to minimize service interruption through redundancy and failover?

  1. High availability
  2. Scalability
  3. On-premises architecture
  4. Real-time operating system (RTOS)

Correct Answer: A

 

Correct Answer

Answer A is correct because High availability means architecture designed to minimize service interruption through redundancy and failover.

Incorrect Answers

Answer B is incorrect because Scalability addresses a different requirement. Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources.

Answer C is incorrect because On-premises architecture represents a different security function. On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization.

Answer D is incorrect because Real-time operating system (RTOS) would fit a different scenario. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

 

Question 18

To continue or restore essential functions after faults or attacks, which security approach should be selected?

  1. Centralized architecture
  2. Decentralized architecture
  3. Resilience
  4. Internet of Things (IoT)

Correct Answer: C

 

Correct Answer

Answer C is correct because Resilience means the ability of a system or organization to withstand disruption and recover acceptable operation.

Incorrect Answers

Answer A is incorrect because Centralized architecture addresses a different security requirement. Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service.

Answer B is incorrect because Decentralized architecture would fit a different scenario. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

Answer D is incorrect because Internet of Things (IoT) addresses a different requirement. Internet of Things (IoT) refers to network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles.

 

Question 19

What is the ability of an architecture to handle increased load by adding or expanding resources?

  1. Scalability
  2. Software-defined networking (SDN)
  3. Virtualization
  4. Logical segmentation

Correct Answer: A

 

Correct Answer

Answer A is correct because Scalability means the ability of an architecture to handle increased load by adding or expanding resources.

Incorrect Answers

Answer B is incorrect because Software-defined networking (SDN) addresses a different requirement. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer C is incorrect because Virtualization represents a different security function. Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Answer D is incorrect because Logical segmentation would fit a different scenario. Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

 

Question 20

To change who bears defined portions of risk rather than eliminating the underlying threat, which security approach should be selected?

  1. Resilience
  2. Risk transference
  3. Cloud shared-responsibility model
  4. Microservices architecture

Correct Answer: B

 

Correct Answer

Answer B is correct because Risk transference means shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements.

Incorrect Answers

Answer A is incorrect because Resilience addresses a different security requirement. Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation.

Answer C is incorrect because Cloud shared-responsibility model addresses a different requirement. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer D is incorrect because Microservices architecture would fit a different scenario. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 21

To determine which party must secure specific layers, configurations, identities, and data, which security approach should be selected?

  1. High availability
  2. Cloud shared-responsibility model
  3. Logical segmentation
  4. Scalability

Correct Answer: B

 

Correct Answer

Answer B is correct because Cloud shared-responsibility model means a division of security duties between a cloud service provider and the customer that varies by service model.

Incorrect Answers

Answer A is incorrect because High availability represents a different security function. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer C is incorrect because Logical segmentation would fit a different scenario. Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

Answer D is incorrect because Scalability addresses a different security requirement. Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources.

 

Question 22

What is an environment combining on-premises resources with cloud or other externally hosted services?

  1. Software-defined networking (SDN)
  2. Air-gapped network
  3. Hybrid architecture
  4. ICS/SCADA

Correct Answer: C

 

Correct Answer

Answer C is correct because Hybrid architecture means an environment combining on-premises resources with cloud or other externally hosted services.

Incorrect Answers

Answer A is incorrect because Software-defined networking (SDN) addresses a different requirement. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer B is incorrect because Air-gapped network represents a different security function. Air-gapped network refers to a network intentionally isolated from other networks through physical separation.

Answer D is incorrect because ICS/SCADA addresses a different security requirement. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

 

Question 23

To create repeatable, reviewable, and automatable infrastructure configurations, which security approach should be selected?

  1. Scalability
  2. Microservices architecture
  3. Risk transference
  4. Infrastructure as code (IaC)

Correct Answer: D

 

Correct Answer

Answer D is correct because Infrastructure as code (IaC) means definition and deployment of infrastructure through machine-readable configuration or code.

Incorrect Answers

Answer A is incorrect because Scalability would fit a different scenario. Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources.

Answer B is incorrect because Microservices architecture represents a different security function. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

Answer C is incorrect because Risk transference addresses a different security requirement. Risk transference refers to shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements.

 

Question 24

What is a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services?

  1. Decentralized architecture
  2. ICS/SCADA
  3. Serverless architecture
  4. Real-time operating system (RTOS)

Correct Answer: C

 

Correct Answer

Answer C is correct because Serverless architecture means a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Incorrect Answers

Answer A is incorrect because Decentralized architecture addresses a different requirement. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

Answer B is incorrect because ICS/SCADA represents a different security function. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

Answer D is incorrect because Real-time operating system (RTOS) addresses a different security requirement. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

 

Question 25

To segment application functionality and scale components independently, which security approach should be selected?

  1. Serverless architecture
  2. High availability
  3. Virtualization
  4. Microservices architecture

Correct Answer: D

 

Correct Answer

Answer D is correct because Microservices architecture means an application model composed of small independently deployable services communicating through defined interfaces.

Incorrect Answers

Answer A is incorrect because Serverless architecture addresses a different security requirement. Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Answer B is incorrect because High availability would fit a different scenario. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer C is incorrect because Virtualization represents a different security function. Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

 

Question 26

What is a network intentionally isolated from other networks through physical separation?

  1. High availability
  2. Air-gapped network
  3. Logical segmentation
  4. Microservices architecture

Correct Answer: B

 

Correct Answer

Answer B is correct because Air-gapped network means a network intentionally isolated from other networks through physical separation.

Incorrect Answers

Answer A is incorrect because High availability addresses a different security requirement. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

Answer C is incorrect because Logical segmentation represents a different security function. Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

Answer D is incorrect because Microservices architecture addresses a different requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 27

To create security zones while sharing underlying infrastructure, which security approach should be selected?

  1. ICS/SCADA
  2. Serverless architecture
  3. Logical segmentation
  4. Microservices architecture

Correct Answer: C

 

Correct Answer

Answer C is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

Incorrect Answers

Answer A is incorrect because ICS/SCADA represents a different security function. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

Answer B is incorrect because Serverless architecture would fit a different scenario. Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Answer D is incorrect because Microservices architecture addresses a different security requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 28

Which networking model separates centralized control logic from packet-forwarding functions?

  1. Real-time operating system (RTOS)
  2. Serverless architecture
  3. Microservices architecture
  4. Software-defined networking (SDN)

Correct Answer: D

 

Correct Answer

Answer D is correct because Software-defined networking (SDN) means a networking model that separates centralized control logic from packet-forwarding functions.

Incorrect Answers

Answer A is incorrect because Real-time operating system (RTOS) addresses a different security requirement. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

Answer B is incorrect because Serverless architecture represents a different security function. Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.

Answer C is incorrect because Microservices architecture addresses a different requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 29

To retain direct control over hardware while assuming more operational responsibility, which security approach should be selected?

  1. On-premises architecture
  2. Decentralized architecture
  3. Cloud shared-responsibility model
  4. Air-gapped network

Correct Answer: A

 

Correct Answer

Answer A is correct because On-premises architecture means systems operated in facilities and infrastructure controlled directly by the organization.

Incorrect Answers

Answer B is incorrect because Decentralized architecture represents a different security function. Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations.

Answer C is incorrect because Cloud shared-responsibility model addresses a different security requirement. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer D is incorrect because Air-gapped network would fit a different scenario. Air-gapped network refers to a network intentionally isolated from other networks through physical separation.

 

Question 30

What is a design in which key control, processing, or management functions are concentrated in a central location or service?

  1. Centralized architecture
  2. Cloud shared-responsibility model
  3. Virtualization
  4. Infrastructure as code (IaC)

Correct Answer: A

 

Correct Answer

Answer A is correct because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service.

Incorrect Answers

Answer B is incorrect because Cloud shared-responsibility model addresses a different security requirement. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer C is incorrect because Virtualization represents a different security function. Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Answer D is incorrect because Infrastructure as code (IaC) addresses a different requirement. Infrastructure as code (IaC) refers to definition and deployment of infrastructure through machine-readable configuration or code.

 

Question 31

To reduce reliance on a single control point and support local autonomy, which security approach should be selected?

  1. Software-defined networking (SDN)
  2. Real-time operating system (RTOS)
  3. High availability
  4. Decentralized architecture

Correct Answer: D

 

Correct Answer

Answer D is correct because Decentralized architecture means a design that distributes control or processing across multiple independent components or locations.

Incorrect Answers

Answer A is incorrect because Software-defined networking (SDN) represents a different security function. Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions.

Answer B is incorrect because Real-time operating system (RTOS) addresses a different security requirement. Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements.

Answer C is incorrect because High availability would fit a different scenario. High availability refers to architecture designed to minimize service interruption through redundancy and failover.

 

Question 32

Which term describes operating-system-level isolation that packages applications and dependencies into lightweight containers?

  1. Logical segmentation
  2. Cloud shared-responsibility model
  3. Containerization
  4. Microservices architecture

Correct Answer: C

 

Correct Answer

Answer C is correct because Containerization means operating-system-level isolation that packages applications and dependencies into lightweight containers.

Incorrect Answers

Answer A is incorrect because Logical segmentation addresses a different security requirement. Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

Answer B is incorrect because Cloud shared-responsibility model represents a different security function. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer D is incorrect because Microservices architecture addresses a different requirement. Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces.

 

Question 33

To consolidate workloads while maintaining logical separation, which security approach should be selected?

  1. ICS/SCADA
  2. Virtualization
  3. Cloud shared-responsibility model
  4. Air-gapped network

Correct Answer: B

 

Correct Answer

Answer B is correct because Virtualization means abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.

Incorrect Answers

Answer A is incorrect because ICS/SCADA addresses a different security requirement. ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes.

Answer C is incorrect because Cloud shared-responsibility model represents a different security function. Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model.

Answer D is incorrect because Air-gapped network would fit a different scenario. Air-gapped network refers to a network intentionally isolated from other networks through physical separation.

 

Question 34

Which term describes network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles?

  1. Centralized architecture
  2. Internet of Things (IoT)
  3. Resilience
  4. Scalability

Correct Answer: B

 

Correct Answer

Answer B is correct because Internet of Things (IoT) means network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles.

Incorrect Answers

Answer A is incorrect because Centralized architecture addresses a different security requirement. Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service.

Answer C is incorrect because Resilience represents a different security function. Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation.

Answer D is incorrect because Scalability addresses a different requirement. Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources.

 

Question 35

To protect operational technology where safety and availability are primary concerns, which security approach should be selected?

  1. Containerization
  2. Centralized architecture
  3. ICS/SCADA
  4. Logical segmentation

Correct Answer: C

 

Correct Answer

Answer C is correct because ICS/SCADA means industrial control and supervisory systems used to monitor or control physical processes.

Incorrect Answers

Answer A is incorrect because Containerization addresses a different security requirement. Containerization refers to operating-system-level isolation that packages applications and dependencies into lightweight containers.

Answer B is incorrect because Centralized architecture would fit a different scenario. Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service.

Answer D is incorrect because Logical segmentation represents a different security function. Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.

img