Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.
Start practicing
Security Architecture — choose a session length
Free · No account required
Domain overview
Security Architecture is the largest CAS-005 domain, covering how you design resilient systems: secure SDLC, zero trust, hybrid cloud connectivity, cryptographic agility, and network segmentation. Questions are scenario-based, asking you to select controls, principles, or technologies that satisfy stated requirements rather than recall isolated definitions.
Exam objectives
Selecting NIST-standardized post-quantum algorithms for key encapsulation versus digital signatures
Choosing secure SDLC activities belonging to development, testing, and deployment phases
Applying zero trust principles such as least privilege and explicit verification to designs
Designing hybrid cloud connectivity using dedicated private links instead of public internet
Confusing post-quantum KEM algorithms with signature algorithms, or assuming all NIST selections serve the same cryptographic purpose
Placing requirements, threat modeling, or security testing in the wrong SDLC phase when asked to choose activities
Treating zero trust as a product or VPN replacement rather than an architecture of continuous verification and least privilege
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?
2An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?
3A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?
4An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?
5During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?
6A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?
7A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?
8During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?
9An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?
10A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)
11An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)
12A security architect is designing a zero-trust architecture for a multi-cloud environment. Which principle is essential for enforcing identity-centric micro-segmentation?
13An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?
14During a secure SDLC, a development team wants to identify vulnerabilities in running code. Which type of testing should be performed?
15A security team is hardening a Kubernetes cluster. Which control should be implemented to restrict a container's system calls to only those required by the application?
16An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?
17A security architect is designing a public key infrastructure (PKI). Which component is responsible for issuing and revoking certificates?
18A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?
19An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?
20A security analyst is investigating an API that uses JSON Web Tokens (JWT) for authentication. Which field in a JWT contains the token expiration time?
21A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?
22A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?
23An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?
24A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?
25A company is migrating to a public cloud and wants to ensure they understand their security responsibilities. According to the shared responsibility model, which of the following is typically the responsibility of the cloud customer?
26A security engineer is designing a secure hybrid cloud connection between an on-premises data center and AWS. Which service provides a dedicated, private network connection that bypasses the public internet?
27An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?
28During a threat modeling exercise for a new web application, the team identifies that the application uses JWT for authentication. Which vulnerability is most likely if the server does not properly verify the JWT signature?
29A security architect is implementing defense-in-depth for a critical application. Which of the following is an example of a detective control?
30A security team is hardening a Kubernetes cluster. Which resource should be used to define fine-grained rules for which pods can communicate with each other?
31A company uses an API gateway to manage their microservices. Which security control should the gateway enforce to prevent abuse from excessive API calls?
32A security administrator needs to ensure that only authorized devices can access the corporate network. Which technology would best enforce this requirement at the network access layer?
33A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)
34An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)
35A security team is implementing a secure SDLC for a new application. Which THREE activities should be included as part of the development phase? (Choose three.)
36A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?
37A company uses a hybrid cloud model with workloads on AWS and on-premises. They need to ensure secure connectivity between the two environments with high bandwidth and low latency, bypassing the public internet. Which solution should they implement?
38An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?
39Which technology is used to discover and control cloud applications, enforce security policies, and provide visibility into cloud usage?
40A security architect is designing a cryptographic system for a government agency that must protect classified data for the next 30 years. The agency is concerned about the threat from quantum computers. Which NIST post-quantum cryptography algorithm is recommended for key encapsulation?
41An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?
42A DevOps team integrates security into the CI/CD pipeline. They want to identify vulnerabilities in open-source libraries used by their application. Which tool or practice is specifically designed for this purpose?
43In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?
44A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?
45An organization uses a multi-cloud strategy with workloads on AWS, Azure, and GCP. They need a single tool to monitor and enforce security configurations across all cloud environments. Which cloud security solution is best suited for this requirement?
46Which of the following best describes the security benefit of using an API gateway in a microservices architecture?
47A company is migrating to immutable infrastructure for its production environment. The security architect needs to ensure that any changes to the infrastructure are made by replacing instances, not by modifying existing ones. Which security advantage does immutable infrastructure provide?
48A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?
49A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?
50Which of the following is a core principle of the Zero Trust security model?
51A security architect is designing a cloud security strategy for a company that uses multiple cloud providers. The architect needs a solution that provides visibility into cloud application usage, enforces security policies, and protects data. Which technology is most appropriate?
52An organization is implementing a hybrid cloud architecture and must ensure secure connectivity between its on-premises network and a public cloud VPC. The traffic includes sensitive data that must not traverse the internet. The solution must provide high bandwidth and low latency. Which connectivity option should the architect choose?
53A company is adopting a defense-in-depth strategy. Which of the following is an example of a preventive control at the network layer?
54An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?
55A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?
56Which of the following is a cloud-native security control provided by a cloud service provider to manage user permissions and access to resources?
57An organization is deploying containerized applications and needs to enforce security policies that restrict the system calls a container can make. Which Linux security module should be used?
58A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?
59In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?
60An organization wants to implement infrastructure as code (IaC) with immutable infrastructure. Which security benefit does immutable infrastructure provide?
61A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)
62A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)
63In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?
64A security architect is designing a hybrid cloud environment. The organization requires low-latency, private connectivity between on-premises and a public cloud provider, bypassing the public internet. Which solution best meets this requirement?
65An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?
66A company uses a CASB to monitor cloud application usage. Which primary function does a CASB provide for enforcing security policies between users and cloud services?
67A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?
68An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?
69In the shared responsibility model for cloud security, which of the following is generally the responsibility of the cloud customer?
70A security architect is evaluating a SASE solution. Which component of SASE is primarily responsible for inspecting encrypted traffic for threats?
71During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?
72To protect against quantum computing attacks, a security architect is planning to transition to post-quantum cryptography. Which algorithm has been selected by NIST for general encryption (key encapsulation) in the PQC standard?
73A company uses Kubernetes for container orchestration. Which security control should be implemented to enforce that only specific images from a trusted registry can run in the cluster?
74Which cryptographic best practice ensures that a private key remains protected even if the server it is stored on is compromised?
75A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?
76A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?
77A security architect is designing a zero trust architecture for a financial services company. Which component is MOST critical to enforce identity-centric access control in a zero trust model?
78In a cloud shared responsibility model, which of the following is typically the customer's responsibility for IaaS?
79A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?
80A security architect is designing a secure connectivity solution between an on-premises data center and a public cloud provider. The solution must provide low latency, high bandwidth, and avoid traversing the public internet. Which approach BEST meets these requirements?
81During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?
82A container security team wants to enforce that containers run with the least privileges possible. Which Linux security module can be used to restrict system calls available to a container?
83An organization is designing a PKI to issue certificates to thousands of IoT devices. Which architectural decision will BEST support automated certificate lifecycle management?
84A security analyst is reviewing a Kubernetes cluster and wants to ensure that only authorized users can create or modify pods. Which Kubernetes object should be configured to enforce this?
85A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?
86A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)
87A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)
88An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)
89Which of the following is a key principle of the zero trust security model?
90A company is migrating its workloads to a public cloud and wants to ensure it understands the division of security responsibilities. Which model defines the demarcation of security controls between the cloud provider and the customer?
91An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?
92A security architect is designing a secure connection between an on-premises data center and a cloud provider's virtual network. The connection must be private, low-latency, and not traverse the public internet. Which solution should they recommend?
93Which of the following is a primary function of a Cloud Access Security Broker (CASB)?
94An organization is adopting a DevSecOps approach and wants to integrate security early in the development lifecycle. Which practice involves creating visual representations of threats and identifying potential attack vectors during the design phase?
95A company is deploying containerized applications on Kubernetes and needs to ensure that only authorized images are run in the cluster. Which Kubernetes resource should be used to enforce policies on what containers can run, including image source restrictions?
96Which of the following is a benefit of using an immutable infrastructure approach?
97An organization uses a hardware security module (HSM) to protect cryptographic keys. Which aspect of key management does an HSM primarily address?
98A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?
99An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?
100Which of the following is a key feature of TLS 1.3 compared to earlier versions?
101A security architect is designing a zero trust network architecture and needs to implement micro-segmentation. Which TWO of the following techniques are commonly used to achieve micro-segmentation? (Select TWO).
102A company is implementing API security for its web services. Which THREE of the following are considered best practices for securing APIs? (Select THREE).
103A security architect is designing a zero trust architecture for a financial institution. Which principle is fundamental to the zero trust model?
104A company is migrating critical workloads to AWS and must secure data at rest. They need to maintain control over the encryption keys. Which service should they use to meet this requirement?
105An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?
106A security analyst is reviewing a Kubernetes cluster's security configuration. Which component should be used to ensure that only authorized pods can communicate with each other?
107During a threat modeling exercise for a new web application, the team identifies a risk of API abuse due to lack of rate limiting. Which security control should be implemented at the API gateway to mitigate this risk?
108A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?
109A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?
110A company uses a multi-cloud strategy with workloads in AWS and Azure. They need a centralized solution to enforce consistent security policies across both cloud environments. Which type of tool should they deploy?
111An organization is migrating to an immutable infrastructure model for its containerized applications. Which practice is essential to ensure the integrity of the immutable infrastructure?
112A security engineer is hardening a Kubernetes environment. Which THREE of the following are effective controls for securing the cluster? (Select THREE.)
113Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)
114A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)
115A company is implementing a secure SDLC and wants to integrate application security testing early. Which THREE tools are most appropriate for shift-left security? (Select THREE.)
116A financial institution is implementing a secure software development lifecycle (SSDLC) for a new web application that will handle sensitive transactions. The security architect must ensure that application security testing is integrated into the development process. Which THREE testing techniques should be used to identify vulnerabilities early and throughout the lifecycle? (Choose THREE.)
117An organization is planning to modernize its cryptographic infrastructure to protect sensitive data for the next 10 years. The security architect must consider future threats from quantum computing. Which TWO quantum-resistant algorithms should the architect prioritize for key encapsulation and digital signatures? (Choose TWO.)
118A security architect is designing a hybrid environment in which on-premises applications must consume APIs hosted in a public cloud. The architect wants to ensure that if the primary cloud region fails, API consumers continue to receive responses without changing client configuration. Which design element BEST satisfies this requirement?
119A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?
120A security architect at a financial services firm must ensure that virtual machine workloads on a private cloud cannot execute unauthorized binaries, even if an attacker gains root access. The solution must enforce policy at the hypervisor layer without relying on agents inside the guest OS. Which of the following should the architect implement?
121A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and new containerized workloads. The architect must reduce lateral movement while minimizing disruption to existing traffic flows. (Choose two.)
122A healthcare provider must allow clinicians to access patient records from personal mobile devices while ensuring that data cannot be copied to unauthorized apps or stored locally. The organization wants to enforce this without managing the entire device. Which of the following should the security architect implement?
123A security architect at a healthcare provider must design a solution that lets clinicians access patient records from managed laptops and personal tablets without exposing the internal electronic health record (EHR) network. The requirement is that no inbound firewall ports be opened and that access decisions evaluate device posture and user identity on every session. Which solution best meets these requirements?
124A security architect is designing a system that must detect tampering with archived audit logs even if an attacker later gains administrative access to the log storage. The logs must remain verifiable for seven years without exposing their contents to the storage provider. Which design BEST meets these requirements?
125A financial services firm is designing a microsegmentation strategy for its VMware-based private cloud. The security team wants to enforce east-west policy based on workload identity rather than IP address, and it must survive IP address changes during automated redeployments. Which approach best satisfies these requirements?
126A financial services company is designing a hybrid cloud environment. The security architect must ensure that data in transit between the on-premises data center and the cloud provider is protected against interception and that the cloud provider cannot read the data. The company also needs to meet strict compliance requirements for key management. Which of the following should the architect implement to BEST meet these requirements?
127A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)
128A security architect is designing a microsegmentation strategy for a data center hosting a three-tier application (web, application, database). The organization wants to enforce least-privilege east-west traffic without relying on IP addresses, and must ensure that workloads can move between hypervisors without requiring rule changes. Which technology best meets these requirements?
129A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The organization wants to minimize the impact on application performance and avoid modifying the application code. Which of the following should the architect implement?
130A financial services firm runs its customer portal on a Kubernetes cluster in AWS. During a penetration test, an attacker who compromised a front-end pod moved laterally to a database pod by directly connecting to its IP address, even though no NetworkPolicy existed. The security architect must implement a control that enforces least-privilege communication between pods and blocks all unauthorized east-west traffic by default. Which of the following should the architect implement?
131A security architect is evaluating a third-party SaaS provider for a critical business function. The provider will process sensitive customer data and must demonstrate compliance with the organization's security requirements. The architect needs to obtain assurance about the provider's security controls without conducting an on-site audit. Which of the following should the architect request?
132A healthcare provider is designing a new system to process protected health information (PHI) in a public cloud. The security architect must ensure that data is encrypted at rest and that the organization retains full control over the encryption keys, including the ability to revoke access immediately if a cloud administrator account is compromised. The cloud provider must not be able to decrypt the data. Which of the following key management approaches BEST meets these requirements?
133A security architect at a healthcare provider must ensure that electronic protected health information (ePHI) stored in an on-premises Microsoft SQL Server database is unreadable if the physical media is stolen. The organization has strict performance requirements and cannot tolerate application changes or key management outside its own hardware security modules (HSMs). Which SQL Server feature BEST meets these requirements?
134A healthcare provider must allow clinicians to access a SaaS electronic health record from unmanaged personal devices without installing agents. The security architect needs to enforce contextual access decisions based on device posture, user identity, and location, while keeping the EHR session isolated from the local browser. Which of the following should the architect implement?
135A security architect at a financial services firm is designing the network for a new containerized trading platform. The platform must enforce Layer 7 policy, provide mutual TLS between all microservices, and eliminate the need to reconfigure each application for cryptographic identity. Which architecture should the architect implement?
136A healthcare organization is designing a new system to store patient records. The security architect must ensure that data at rest is encrypted and that cryptographic keys are rotated regularly without re-encrypting the entire database. Which of the following techniques should be used?
137A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?
138A company is modernizing its security operations center and wants to correlate logs from firewalls, endpoints, and cloud services in a single platform that supports long-term retention and custom detection rules. Which technology best fits this requirement?
139A security architect is designing a microsegmentation strategy for a hybrid cloud environment. The organization wants to enforce least-privilege network access between workloads, prevent lateral movement, and maintain visibility into east-west traffic. Which TWO of the following controls are MOST appropriate to achieve these goals? (Choose two.)
140A healthcare provider must ensure that electronic protected health information (ePHI) stored in a public cloud object storage bucket is unreadable to the cloud provider and remains confidential even if the provider's infrastructure is compromised. The security architect wants to use a customer-managed key that never leaves the organization's on-premises hardware security module (HSM). Which approach should the architect implement?
141A security architect at a defense contractor must protect Controlled Unclassified Information (CUI) that flows between an on-premises data center and a government cloud enclave. The requirement states that data must remain confidential even if a cloud provider's hypervisor is compromised, and the provider must not be able to access plaintext at any layer. The architect needs a control that cryptographically isolates tenant workloads from the provider and from other tenants. Which of the following BEST satisfies this requirement?
142A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)
143A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)
144A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?
145A security architect is designing a platform for a hospital network. Clinical staff must access patient records from managed workstations, while third-party billing contractors use unmanaged personal laptops. The architect wants a single architecture that continuously validates device posture and user identity before granting access to each microservice, regardless of network location. Which approach should the architect implement?
146A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?
147A financial services firm is designing its identity architecture for a Zero Trust program. Auditors require that authentication strength be continuously evaluated and that a compromised endpoint lose access to sensitive trading applications even after the user has already authenticated. The security architect must select TWO capabilities that directly support continuous, context-aware authorization decisions. (Choose two.)
148A financial services firm is designing a hybrid identity architecture. Employees authenticate on-premises to Active Directory Domain Services, while applications are hosted in multiple SaaS and IaaS providers. The security architect must ensure that a compromised on-premises domain controller cannot be used to forge tokens that grant access to cloud applications, and that cloud access decisions reflect real-time on-premises risk signals. Which of the following BEST achieves these goals?
149A security architect at a financial services firm is designing the network segmentation for a new containerized trading platform running on Kubernetes. The platform must isolate workloads so that a compromise of the public-facing web tier cannot directly reach the database tier. The architect wants to enforce this isolation natively within the cluster and have policies applied automatically as new pods are scheduled. Which of the following should the architect implement?
150A multinational retailer needs to protect cardholder data across its e-commerce platform, which spans on-premises and multiple cloud providers. The security architect must implement a solution that discovers sensitive data, classifies it consistently, and enforces encryption and access policies wherever the data resides, without relying on a single cloud provider's native tools. Which of the following should the architect implement?
151A multinational corporation is designing a hybrid cloud architecture that spans an on-premises data center and two public cloud regions. The security architect needs to ensure that all administrative access to cloud resources is brokered through a central identity provider, that access decisions consider device posture, and that no long-lived credentials are stored in the cloud. Which combination of technologies should the architect implement?
152A security architect is reviewing the network design for a new branch office. The organization wants to ensure that all traffic from the branch is inspected for malware and that users are authenticated before accessing cloud applications, regardless of their location. Which technology should the architect recommend?
153A security architect at a financial services firm is designing a microsegmentation strategy for a data center running both virtual machines and containerized workloads. The architect must reduce east-west lateral movement and enforce least-privilege communication between tiers. Which TWO design elements are most appropriate? (Choose two.)
154A healthcare organization is architecting a microsegmentation strategy for its hybrid data center. The security architect must limit lateral movement between workloads, enforce policy based on workload identity rather than IP addresses, and maintain visibility into inter-workload flows. Which TWO of the following controls BEST support these requirements? (Choose two.)
155A security architect is designing a hybrid identity solution for a company that wants to enforce device-based conditional access for Microsoft 365. Employees use personal Android and iOS devices, and the company wants to ensure that only compliant devices can access email and SharePoint. The architect must minimize on-premises infrastructure and avoid a full VPN. Which solution should the architect recommend?
156A security architect is designing segmentation for a manufacturing network where legacy programmable logic controllers cannot be patched or run endpoint agents. The architect wants to prevent a compromised business workstation from initiating connections to the controllers while still allowing the controllers to send telemetry to a historian server. Which of the following design elements best achieves this objective?
157A healthcare provider is designing a data protection scheme for patient records stored in a cloud object store. Regulatory requirements mandate that encryption keys never leave the organization's on-premises hardware security modules (HSMs), while the cloud provider must still be able to perform server-side encryption on upload. The architect needs a key management approach that satisfies both constraints. Which of the following should the architect implement?
158A software company wants to ensure that every container image deployed to production is free of known critical vulnerabilities and is cryptographically signed by its build pipeline. The security architect must implement controls that verify the signature and vulnerability status before the container runtime starts the image. Which of the following should the architect implement?
159A security architect is designing a microsegmentation strategy for a data center that hosts both legacy virtual machines and modern containerized workloads. The architect must ensure that security policies follow the workload regardless of its location and that lateral movement is restricted even if a host is compromised. (Choose two.)
160A security architect is designing a system that must provide confidentiality and integrity for data at rest and in transit. The organization wants to minimize the risk of key compromise and ensure that a single compromised key does not expose all data. Which key management strategy best meets these requirements?
161A software company wants to strengthen the integrity of its build pipeline. Developers currently commit code directly to the main branch, and build servers pull dependencies from public repositories without verification. The security architect must ensure that only reviewed code is built and that dependencies have not been tampered with. Which combination of controls best addresses these requirements?
162A global retailer is deploying a microsegmentation strategy in its data center to limit lateral movement after a breach. The security architect must enforce policy based on workload identity and allow only required east-west flows, even when workloads are migrated between hosts. Which of the following should be implemented?
163A retail company is designing a new payment processing environment and wants to reduce the scope of its PCI DSS assessment. The architect proposes isolating the cardholder data environment from the rest of the corporate network so that most systems fall outside the audit boundary. Which of the following design approaches best supports this goal?
164A financial services company is designing a secure multi-tenant SaaS application hosted on AWS. The security architect must ensure that each tenant's data is isolated and that encryption keys are unique per tenant, while allowing the company to manage keys centrally. Which AWS service should the architect use to meet these requirements?
165A security architect is designing a data loss prevention (DLP) program for a global enterprise that uses Microsoft 365, endpoint devices, and a custom web application. The requirement is to detect and block sensitive data exfiltration across all three channels while minimizing false positives caused by legitimate business data that resembles regulated data. The architect needs a control that classifies data consistently and applies policy at the point of egress. Which of the following BEST meets this requirement?
166A security architect is evaluating a cloud service provider's ability to support a customer's compliance with PCI DSS. The customer will store cardholder data in the cloud. The architect needs to determine which party is responsible for configuring encryption of the data at rest and managing the encryption keys. According to the shared responsibility model, which of the following is the MOST accurate statement?
167A software company is designing an internal developer platform where engineers need short-lived credentials to access production databases. The security architect wants to eliminate long-lived static database passwords, bind access to the identity of the calling workload, and automatically revoke credentials when a deployment is removed. Which of the following should the architect implement?
168A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?
169A security architect is evaluating a software-defined wide area network (SD-WAN) solution to connect branch offices to cloud services. The architect wants to ensure that traffic from branches to cloud applications is inspected for threats without backhauling all traffic to the data center. Which capability should the architect prioritize?
170A startup is building a new application on a public cloud and wants to minimize the attack surface of its virtual machines. The security architect recommends replacing SSH key-based administration with a model where no inbound management ports are exposed and access is granted per session with short-lived credentials. Which of the following should be implemented?
171A multinational retailer operates an on-premises data center and two public cloud regions. Regulations require that customer payment data never leave the home country, but the company wants centralized security analytics. The architect needs a design that keeps raw payment records local while enabling global threat detection. Which design best meets these constraints?
172A security architect is designing a zero trust architecture for a company with a large remote workforce. The requirement is to verify device health and user identity for every session to internal applications, regardless of network location, and to prevent session hijacking after initial authentication. Which of the following BEST meets these requirements?
173A security architect is designing a zero trust network access (ZTNA) solution for a company with remote workers. The architect must ensure that access to internal applications is granted based on user identity and device posture, without exposing applications to the internet. Which TWO design elements are essential for this ZTNA implementation? (Choose two.)
174A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?
175A security architect is designing a network for a hospital that must keep its electronic health record (EHR) servers completely isolated from the internet while still allowing a small group of vendors to perform remote maintenance. The vendors use laptops that are not managed by the hospital. The architect proposes a jump host architecture. Which of the following designs best satisfies the requirement while minimizing risk?
176A security architect is reviewing the company's incident response plan and wants to ensure that the team can detect and respond to threats in real time across endpoints, networks, and cloud workloads. The architect needs a solution that correlates events from multiple sources and provides automated response actions. Which technology should the architect recommend?
177A security architect for a healthcare provider must ensure that a new patient portal can exchange data with an external partner's system without the two organizations having to share or manage each other's identity credentials. The portal must support SAML assertions, provide centralized session revocation, and allow attribute-based authorization decisions at the relying party. Which of the following should the architect implement?
178A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and modern containerized workloads. The organization wants to enforce least-privilege network access between workloads without relying on IP addresses or VLANs, and it requires the ability to define policy based on workload identity and tags that follow the workload across environments. Which technology best meets these requirements?
179A security architect is reviewing the identity architecture for a company that uses a hybrid cloud. Employees authenticate to an on-premises Active Directory Domain Services (AD DS) domain and also need to access SaaS applications. The company wants to avoid storing separate passwords for each SaaS application and wants to enforce on-premises account status and group membership in real time. Which of the following should the architect implement?
180A financial services firm is designing a new internal API platform. The security architect must ensure that every service-to-service call is authenticated, that a compromised service cannot impersonate another service, and that credentials are short-lived and automatically rotated. The platform runs on Kubernetes and uses an external secrets manager. Which of the following designs best meets these requirements?
181A healthcare organization is architecting a secure data exchange with a partner hospital. The partners need to share patient records in near real time, but they do not want to expose their internal databases directly. The security architect must ensure that only specific, authorized fields are exchanged, that the data is validated against a predefined schema, and that the exchange is auditable and resistant to tampering. Which approach best satisfies these requirements?
182A security architect is designing a data loss prevention (DLP) program for a company that uses Microsoft 365 and a SaaS CRM. The architect must reduce false positives while still detecting sensitive data leaving the environment. Which TWO capabilities should be prioritized? (Choose two.)
183A security architect is designing a Zero Trust architecture for a multinational corporation. The organization wants to enforce least-privilege access to applications based on device health, user identity, and contextual factors, and it requires continuous verification of trust. Which TWO of the following are core enforcement mechanisms that should be implemented to achieve these goals? (Choose two.)
184A security administrator is reviewing an architecture diagram for a new web application. The diagram shows the application servers in a private subnet, a database in a separate private subnet, and a public load balancer in a public subnet. The administrator wants to ensure that the application servers can retrieve software updates from the internet without being directly reachable from it. Which of the following should the administrator recommend?
185A government agency is designing a system that processes highly sensitive data on a need-to-know basis. The security architect must ensure that access decisions consider the user's clearance level, the data's classification label, and the user's current role, and that users cannot change their own labels. Which of the following access control models best fits these requirements?
186A security architect is reviewing the authentication design for a new customer portal that will be accessed by partners from multiple external organizations. The business wants partners to use their existing corporate identities, avoid creating new passwords for the portal, and allow the home organization to remain the authoritative source for disabling accounts. Which of the following should the architect recommend?
187A security architect is designing a network for a small business that wants to allow employees to use their personal smartphones and tablets to access corporate email and files. The company wants to enforce screen lock, encryption, and remote wipe on these devices without managing the entire device. Which of the following should the architect implement?
188A security architect is designing a microservices-based application deployed on containers in a Kubernetes cluster. The architect needs to implement controls that protect the application from lateral movement in case a container is compromised. Which TWO of the following controls best achieve this goal? (Choose two.)
Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.
The Courseiva CAS-005 question bank contains 188 questions in the Security Architecture domain, covering the 27% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Architecture domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included