Courseiva

CAS-005 · domain

Security Architecture

Security Architecture is the largest CAS-005 domain, covering how you design resilient systems: secure SDLC, zero trust, hybrid cloud connectivity, cryptographic agility, and network segmentation. Questions are scenario-based, asking you to select controls, principles, or technologies that satisfy stated requirements rather than recall isolated definitions.

188 questions36 easy90 medium62 hard

Focused practice

Practice Security Architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Architecture

Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.

Selecting NIST-standardized post-quantum algorithms for key encapsulation versus digital signatures

Choosing secure SDLC activities belonging to development, testing, and deployment phases

Applying zero trust principles such as least privilege and explicit verification to designs

Designing hybrid cloud connectivity using dedicated private links instead of public internet

Watch out for

Common Security Architecture exam traps

  • ▸Confusing post-quantum KEM algorithms with signature algorithms, or assuming all NIST selections serve the same cryptographic purpose
  • ▸Placing requirements, threat modeling, or security testing in the wrong SDLC phase when asked to choose activities
  • ▸Treating zero trust as a product or VPN replacement rather than an architecture of continuous verification and least privilege

Question index

All Security Architecture questions (188)

Click any question to see the full explanation, or start a practice session above.

1

A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?

Hard
2

An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?

Medium
3

A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)

Medium
4

A security architect is evaluating a third-party SaaS provider for a critical business function. The provider will process sensitive customer data and must demonstrate compliance with the organization's security requirements. The architect needs to obtain assurance about the provider's security controls without conducting an on-site audit. Which of the following should the architect request?

Hard
5

A security architect is designing a network for a hospital that must keep its electronic health record (EHR) servers completely isolated from the internet while still allowing a small group of vendors to perform remote maintenance. The vendors use laptops that are not managed by the hospital. The architect proposes a jump host architecture. Which of the following designs best satisfies the requirement while minimizing risk?

Hard
6

A security engineer is designing a secure hybrid cloud connection between an on-premises data center and AWS. Which service provides a dedicated, private network connection that bypasses the public internet?

Medium
7

A security architect is designing a system that must detect tampering with archived audit logs even if an attacker later gains administrative access to the log storage. The logs must remain verifiable for seven years without exposing their contents to the storage provider. Which design BEST meets these requirements?

Hard
8

A security architect is designing a cryptographic system for a government agency that must protect classified data for the next 30 years. The agency is concerned about the threat from quantum computers. Which NIST post-quantum cryptography algorithm is recommended for key encapsulation?

Medium
9

A financial services company is designing a secure multi-tenant SaaS application hosted on AWS. The security architect must ensure that each tenant's data is isolated and that encryption keys are unique per tenant, while allowing the company to manage keys centrally. Which AWS service should the architect use to meet these requirements?

Hard
10

A security architect is designing a public key infrastructure (PKI). Which component is responsible for issuing and revoking certificates?

Medium
11

A company uses an API gateway to manage their microservices. Which security control should the gateway enforce to prevent abuse from excessive API calls?

Medium
12

Which of the following is a key principle of the zero trust security model?

Easy
13

A multinational retailer needs to protect cardholder data across its e-commerce platform, which spans on-premises and multiple cloud providers. The security architect must implement a solution that discovers sensitive data, classifies it consistently, and enforces encryption and access policies wherever the data resides, without relying on a single cloud provider's native tools. Which of the following should the architect implement?

Hard
14

A financial services firm is designing a microsegmentation strategy for its VMware-based private cloud. The security team wants to enforce east-west policy based on workload identity rather than IP address, and it must survive IP address changes during automated redeployments. Which approach best satisfies these requirements?

Hard
15

A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?

Hard
16

A healthcare provider must allow clinicians to access patient records from personal mobile devices while ensuring that data cannot be copied to unauthorized apps or stored locally. The organization wants to enforce this without managing the entire device. Which of the following should the security architect implement?

Hard
17

An organization uses a hardware security module (HSM) to protect cryptographic keys. Which aspect of key management does an HSM primarily address?

Medium
18

A global retailer is deploying a microsegmentation strategy in its data center to limit lateral movement after a breach. The security architect must enforce policy based on workload identity and allow only required east-west flows, even when workloads are migrated between hosts. Which of the following should be implemented?

Medium
19

A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)

Medium
20

A financial services firm runs its customer portal on a Kubernetes cluster in AWS. During a penetration test, an attacker who compromised a front-end pod moved laterally to a database pod by directly connecting to its IP address, even though no NetworkPolicy existed. The security architect must implement a control that enforces least-privilege communication between pods and blocks all unauthorized east-west traffic by default. Which of the following should the architect implement?

Medium
21

A financial services firm is designing a hybrid identity architecture. Employees authenticate on-premises to Active Directory Domain Services, while applications are hosted in multiple SaaS and IaaS providers. The security architect must ensure that a compromised on-premises domain controller cannot be used to forge tokens that grant access to cloud applications, and that cloud access decisions reflect real-time on-premises risk signals. Which of the following BEST achieves these goals?

Hard
22

Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)

Easy
23

A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?

Medium
24

A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)

Medium
25

An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)

Hard
26

An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?

Easy
27

A software company wants to strengthen the integrity of its build pipeline. Developers currently commit code directly to the main branch, and build servers pull dependencies from public repositories without verification. The security architect must ensure that only reviewed code is built and that dependencies have not been tampered with. Which combination of controls best addresses these requirements?

Medium
28

A healthcare organization is architecting a microsegmentation strategy for its hybrid data center. The security architect must limit lateral movement between workloads, enforce policy based on workload identity rather than IP addresses, and maintain visibility into inter-workload flows. Which TWO of the following controls BEST support these requirements? (Choose two.)

Medium
29

A financial services company is designing a hybrid cloud environment. The security architect must ensure that data in transit between the on-premises data center and the cloud provider is protected against interception and that the cloud provider cannot read the data. The company also needs to meet strict compliance requirements for key management. Which of the following should the architect implement to BEST meet these requirements?

Medium
30

An organization is migrating to an immutable infrastructure model for its containerized applications. Which practice is essential to ensure the integrity of the immutable infrastructure?

Hard
31

Which cryptographic best practice ensures that a private key remains protected even if the server it is stored on is compromised?

Easy
32

A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?

Medium
33

In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?

Easy
34

A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?

Medium
35

A security architect is designing a system that must provide confidentiality and integrity for data at rest and in transit. The organization wants to minimize the risk of key compromise and ensure that a single compromised key does not expose all data. Which key management strategy best meets these requirements?

Hard
36

A security team is hardening a Kubernetes cluster. Which resource should be used to define fine-grained rules for which pods can communicate with each other?

Medium
37

An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?

Medium
38

A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?

Medium
39

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and new containerized workloads. The architect must reduce lateral movement while minimizing disruption to existing traffic flows. (Choose two.)

Medium
40

A security architect at a financial services firm is designing a microsegmentation strategy for a data center running both virtual machines and containerized workloads. The architect must reduce east-west lateral movement and enforce least-privilege communication between tiers. Which TWO design elements are most appropriate? (Choose two.)

Hard
41

A security architect is designing a zero trust network access (ZTNA) solution for a company with remote workers. The architect must ensure that access to internal applications is granted based on user identity and device posture, without exposing applications to the internet. Which TWO design elements are essential for this ZTNA implementation? (Choose two.)

Medium
42

A security architect is designing a cloud security strategy for a company that uses multiple cloud providers. The architect needs a solution that provides visibility into cloud application usage, enforces security policies, and protects data. Which technology is most appropriate?

Medium
43

A security architect is designing a data loss prevention (DLP) program for a global enterprise that uses Microsoft 365, endpoint devices, and a custom web application. The requirement is to detect and block sensitive data exfiltration across all three channels while minimizing false positives caused by legitimate business data that resembles regulated data. The architect needs a control that classifies data consistently and applies policy at the point of egress. Which of the following BEST meets this requirement?

Hard
44

A security architect is designing segmentation for a manufacturing network where legacy programmable logic controllers cannot be patched or run endpoint agents. The architect wants to prevent a compromised business workstation from initiating connections to the controllers while still allowing the controllers to send telemetry to a historian server. Which of the following design elements best achieves this objective?

Hard
45

An organization is adopting a DevSecOps approach and wants to integrate security early in the development lifecycle. Which practice involves creating visual representations of threats and identifying potential attack vectors during the design phase?

Medium
46

A DevOps team integrates security into the CI/CD pipeline. They want to identify vulnerabilities in open-source libraries used by their application. Which tool or practice is specifically designed for this purpose?

Hard
47

A company is migrating critical workloads to AWS and must secure data at rest. They need to maintain control over the encryption keys. Which service should they use to meet this requirement?

Medium
48

Which of the following is a benefit of using an immutable infrastructure approach?

Easy
49

A company is adopting a defense-in-depth strategy. Which of the following is an example of a preventive control at the network layer?

Medium
50

During a threat modeling exercise for a new web application, the team identifies a risk of API abuse due to lack of rate limiting. Which security control should be implemented at the API gateway to mitigate this risk?

Medium
51

An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?

Hard
52

A security architect is designing a zero-trust architecture for a multi-cloud environment. Which principle is essential for enforcing identity-centric micro-segmentation?

Medium
53

An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?

Medium
54

In the shared responsibility model for cloud security, which of the following is generally the responsibility of the cloud customer?

Easy
55

A security architect is designing a zero trust architecture for a company with a large remote workforce. The requirement is to verify device health and user identity for every session to internal applications, regardless of network location, and to prevent session hijacking after initial authentication. Which of the following BEST meets these requirements?

Medium
56

An organization uses a multi-cloud strategy with workloads on AWS, Azure, and GCP. They need a single tool to monitor and enforce security configurations across all cloud environments. Which cloud security solution is best suited for this requirement?

Medium
57

An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?

Medium
58

During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?

Hard
59

A security architect is reviewing the identity architecture for a company that uses a hybrid cloud. Employees authenticate to an on-premises Active Directory Domain Services (AD DS) domain and also need to access SaaS applications. The company wants to avoid storing separate passwords for each SaaS application and wants to enforce on-premises account status and group membership in real time. Which of the following should the architect implement?

Medium
60

Which of the following is a primary function of a Cloud Access Security Broker (CASB)?

Easy
61

Which of the following is a key feature of TLS 1.3 compared to earlier versions?

Medium
62

A government agency is designing a system that processes highly sensitive data on a need-to-know basis. The security architect must ensure that access decisions consider the user's clearance level, the data's classification label, and the user's current role, and that users cannot change their own labels. Which of the following access control models best fits these requirements?

Hard
63

A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?

Medium
64

A financial services firm is designing a new internal API platform. The security architect must ensure that every service-to-service call is authenticated, that a compromised service cannot impersonate another service, and that credentials are short-lived and automatically rotated. The platform runs on Kubernetes and uses an external secrets manager. Which of the following designs best meets these requirements?

Hard
65

A company is implementing a secure SDLC and wants to integrate application security testing early. Which THREE tools are most appropriate for shift-left security? (Select THREE.)

Hard
66

An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?

Easy
67

A security architect is designing a microsegmentation strategy for a data center hosting a three-tier application (web, application, database). The organization wants to enforce least-privilege east-west traffic without relying on IP addresses, and must ensure that workloads can move between hypervisors without requiring rule changes. Which technology best meets these requirements?

Medium
68

A healthcare provider is designing a data protection scheme for patient records stored in a cloud object store. Regulatory requirements mandate that encryption keys never leave the organization's on-premises hardware security modules (HSMs), while the cloud provider must still be able to perform server-side encryption on upload. The architect needs a key management approach that satisfies both constraints. Which of the following should the architect implement?

Hard
69

A multinational corporation is designing a hybrid cloud architecture that spans an on-premises data center and two public cloud regions. The security architect needs to ensure that all administrative access to cloud resources is brokered through a central identity provider, that access decisions consider device posture, and that no long-lived credentials are stored in the cloud. Which combination of technologies should the architect implement?

Medium
70

A security architect is designing a Zero Trust architecture for a multinational corporation. The organization wants to enforce least-privilege access to applications based on device health, user identity, and contextual factors, and it requires continuous verification of trust. Which TWO of the following are core enforcement mechanisms that should be implemented to achieve these goals? (Choose two.)

Hard
71

An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?

Hard
72

A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?

Medium
73

An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)

Hard
74

A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?

Easy
75

A security architect is designing a hybrid identity solution for a company that wants to enforce device-based conditional access for Microsoft 365. Employees use personal Android and iOS devices, and the company wants to ensure that only compliant devices can access email and SharePoint. The architect must minimize on-premises infrastructure and avoid a full VPN. Which solution should the architect recommend?

Medium
76

A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)

Hard
77

A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?

Medium
78

An organization wants to implement infrastructure as code (IaC) with immutable infrastructure. Which security benefit does immutable infrastructure provide?

Medium
79

A security architect is designing a microsegmentation strategy for a data center that hosts both legacy virtual machines and modern containerized workloads. The architect must ensure that security policies follow the workload regardless of its location and that lateral movement is restricted even if a host is compromised. (Choose two.)

Hard
80

A security architect is designing a secure connectivity solution between an on-premises data center and a public cloud provider. The solution must provide low latency, high bandwidth, and avoid traversing the public internet. Which approach BEST meets these requirements?

Hard
81

An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?

Hard
82

A security architect is designing a zero trust architecture for a financial services company. Which component is MOST critical to enforce identity-centric access control in a zero trust model?

Medium
83

A security architect is designing a zero trust network architecture and needs to implement micro-segmentation. Which TWO of the following techniques are commonly used to achieve micro-segmentation? (Select TWO).

Medium
84

An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?

Medium
85

An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)

Hard
86

A multinational retailer operates an on-premises data center and two public cloud regions. Regulations require that customer payment data never leave the home country, but the company wants centralized security analytics. The architect needs a design that keeps raw payment records local while enabling global threat detection. Which design best meets these constraints?

Hard
87

A security architect is designing a hybrid cloud environment. The organization requires low-latency, private connectivity between on-premises and a public cloud provider, bypassing the public internet. Which solution best meets this requirement?

Medium
88

A security architect is designing a hybrid environment in which on-premises applications must consume APIs hosted in a public cloud. The architect wants to ensure that if the primary cloud region fails, API consumers continue to receive responses without changing client configuration. Which design element BEST satisfies this requirement?

Medium
89

A security administrator is reviewing an architecture diagram for a new web application. The diagram shows the application servers in a private subnet, a database in a separate private subnet, and a public load balancer in a public subnet. The administrator wants to ensure that the application servers can retrieve software updates from the internet without being directly reachable from it. Which of the following should the administrator recommend?

Easy
90

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?

Easy
91

A security analyst is investigating an API that uses JSON Web Tokens (JWT) for authentication. Which field in a JWT contains the token expiration time?

Easy
92

During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?

Medium
93

An organization is deploying containerized applications and needs to enforce security policies that restrict the system calls a container can make. Which Linux security module should be used?

Medium
94

A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)

Hard
95

A security architect is reviewing the network design for a new branch office. The organization wants to ensure that all traffic from the branch is inspected for malware and that users are authenticated before accessing cloud applications, regardless of their location. Which technology should the architect recommend?

Easy
96

A container security team wants to enforce that containers run with the least privileges possible. Which Linux security module can be used to restrict system calls available to a container?

Hard
97

A security team is implementing a secure SDLC for a new application. Which THREE activities should be included as part of the development phase? (Choose three.)

Hard
98

A company is migrating to a public cloud and wants to ensure they understand their security responsibilities. According to the shared responsibility model, which of the following is typically the responsibility of the cloud customer?

Medium
99

A company uses a CASB to monitor cloud application usage. Which primary function does a CASB provide for enforcing security policies between users and cloud services?

Medium
100

A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)

Medium
101

A security architect is evaluating a cloud service provider's ability to support a customer's compliance with PCI DSS. The customer will store cardholder data in the cloud. The architect needs to determine which party is responsible for configuring encryption of the data at rest and managing the encryption keys. According to the shared responsibility model, which of the following is the MOST accurate statement?

Hard
102

A startup is building a new application on a public cloud and wants to minimize the attack surface of its virtual machines. The security architect recommends replacing SSH key-based administration with a model where no inbound management ports are exposed and access is granted per session with short-lived credentials. Which of the following should be implemented?

Easy
103

A company is migrating to immutable infrastructure for its production environment. The security architect needs to ensure that any changes to the infrastructure are made by replacing instances, not by modifying existing ones. Which security advantage does immutable infrastructure provide?

Hard
104

During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?

Hard
105

A security architect at a defense contractor must protect Controlled Unclassified Information (CUI) that flows between an on-premises data center and a government cloud enclave. The requirement states that data must remain confidential even if a cloud provider's hypervisor is compromised, and the provider must not be able to access plaintext at any layer. The architect needs a control that cryptographically isolates tenant workloads from the provider and from other tenants. Which of the following BEST satisfies this requirement?

Medium
106

A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?

Medium
107

A company uses Kubernetes for container orchestration. Which security control should be implemented to enforce that only specific images from a trusted registry can run in the cluster?

Medium
108

A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)

Hard
109

A security architect is designing a platform for a hospital network. Clinical staff must access patient records from managed workstations, while third-party billing contractors use unmanaged personal laptops. The architect wants a single architecture that continuously validates device posture and user identity before granting access to each microservice, regardless of network location. Which approach should the architect implement?

Medium
110

A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)

Medium
111

A security architect is designing a microservices-based application deployed on containers in a Kubernetes cluster. The architect needs to implement controls that protect the application from lateral movement in case a container is compromised. Which TWO of the following controls best achieve this goal? (Choose two.)

Hard
112

A security team is hardening a Kubernetes cluster. Which control should be implemented to restrict a container's system calls to only those required by the application?

Hard
113

A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?

Medium
114

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?

Easy
115

A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?

Hard
116

A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?

Hard
117

A security analyst is reviewing a Kubernetes cluster's security configuration. Which component should be used to ensure that only authorized pods can communicate with each other?

Easy
118

A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?

Hard
119

A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?

Medium
120

A company is implementing API security for its web services. Which THREE of the following are considered best practices for securing APIs? (Select THREE).

Easy
121

A security architect at a financial services firm is designing the network segmentation for a new containerized trading platform running on Kubernetes. The platform must isolate workloads so that a compromise of the public-facing web tier cannot directly reach the database tier. The architect wants to enforce this isolation natively within the cluster and have policies applied automatically as new pods are scheduled. Which of the following should the architect implement?

Medium
122

A security architect is designing a zero trust architecture for a financial institution. Which principle is fundamental to the zero trust model?

Easy
123

An organization is designing a PKI to issue certificates to thousands of IoT devices. Which architectural decision will BEST support automated certificate lifecycle management?

Medium
124

An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?

Medium
125

A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?

Hard
126

A security administrator needs to ensure that only authorized devices can access the corporate network. Which technology would best enforce this requirement at the network access layer?

Easy
127

An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?

Hard
128

A company uses a hybrid cloud model with workloads on AWS and on-premises. They need to ensure secure connectivity between the two environments with high bandwidth and low latency, bypassing the public internet. Which solution should they implement?

Medium
129

A healthcare provider is designing a new system to process protected health information (PHI) in a public cloud. The security architect must ensure that data is encrypted at rest and that the organization retains full control over the encryption keys, including the ability to revoke access immediately if a cloud administrator account is compromised. The cloud provider must not be able to decrypt the data. Which of the following key management approaches BEST meets these requirements?

Hard
130

A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?

Medium
131

A healthcare provider must allow clinicians to access a SaaS electronic health record from unmanaged personal devices without installing agents. The security architect needs to enforce contextual access decisions based on device posture, user identity, and location, while keeping the EHR session isolated from the local browser. Which of the following should the architect implement?

Hard
132

A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?

Medium
133

A security architect is designing a network for a small business that wants to allow employees to use their personal smartphones and tablets to access corporate email and files. The company wants to enforce screen lock, encryption, and remote wipe on these devices without managing the entire device. Which of the following should the architect implement?

Easy
134

A security architect is reviewing the company's incident response plan and wants to ensure that the team can detect and respond to threats in real time across endpoints, networks, and cloud workloads. The architect needs a solution that correlates events from multiple sources and provides automated response actions. Which technology should the architect recommend?

Easy
135

A security architect is designing a secure connection between an on-premises data center and a cloud provider's virtual network. The connection must be private, low-latency, and not traverse the public internet. Which solution should they recommend?

Medium
136

A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?

Hard
137

A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?

Medium
138

A financial institution is implementing a secure software development lifecycle (SSDLC) for a new web application that will handle sensitive transactions. The security architect must ensure that application security testing is integrated into the development process. Which THREE testing techniques should be used to identify vulnerabilities early and throughout the lifecycle? (Choose THREE.)

Medium
139

A company uses a multi-cloud strategy with workloads in AWS and Azure. They need a centralized solution to enforce consistent security policies across both cloud environments. Which type of tool should they deploy?

Medium
140

A security architect at a healthcare provider must ensure that electronic protected health information (ePHI) stored in an on-premises Microsoft SQL Server database is unreadable if the physical media is stolen. The organization has strict performance requirements and cannot tolerate application changes or key management outside its own hardware security modules (HSMs). Which SQL Server feature BEST meets these requirements?

Medium
141

During a secure SDLC, a development team wants to identify vulnerabilities in running code. Which type of testing should be performed?

Easy
142

An organization is implementing a hybrid cloud architecture and must ensure secure connectivity between its on-premises network and a public cloud VPC. The traffic includes sensitive data that must not traverse the internet. The solution must provide high bandwidth and low latency. Which connectivity option should the architect choose?

Hard
143

A security architect is implementing defense-in-depth for a critical application. Which of the following is an example of a detective control?

Easy
144

To protect against quantum computing attacks, a security architect is planning to transition to post-quantum cryptography. Which algorithm has been selected by NIST for general encryption (key encapsulation) in the PQC standard?

Hard
145

A healthcare organization is designing a new system to store patient records. The security architect must ensure that data at rest is encrypted and that cryptographic keys are rotated regularly without re-encrypting the entire database. Which of the following techniques should be used?

Medium
146

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and modern containerized workloads. The organization wants to enforce least-privilege network access between workloads without relying on IP addresses or VLANs, and it requires the ability to define policy based on workload identity and tags that follow the workload across environments. Which technology best meets these requirements?

Hard
147

A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)

Medium
148

Which of the following is a core principle of the Zero Trust security model?

Easy
149

A security architect is reviewing the authentication design for a new customer portal that will be accessed by partners from multiple external organizations. The business wants partners to use their existing corporate identities, avoid creating new passwords for the portal, and allow the home organization to remain the authoritative source for disabling accounts. Which of the following should the architect recommend?

Easy
150

An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?

Hard
151

A healthcare organization is architecting a secure data exchange with a partner hospital. The partners need to share patient records in near real time, but they do not want to expose their internal databases directly. The security architect must ensure that only specific, authorized fields are exchanged, that the data is validated against a predefined schema, and that the exchange is auditable and resistant to tampering. Which approach best satisfies these requirements?

Medium
152

An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?

Medium
153

A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?

Medium
154

A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?

Medium
155

A healthcare provider must ensure that electronic protected health information (ePHI) stored in a public cloud object storage bucket is unreadable to the cloud provider and remains confidential even if the provider's infrastructure is compromised. The security architect wants to use a customer-managed key that never leaves the organization's on-premises hardware security module (HSM). Which approach should the architect implement?

Hard
156

A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?

Hard
157

An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?

Hard
158

Which of the following best describes the security benefit of using an API gateway in a microservices architecture?

Easy
159

A security architect is evaluating a SASE solution. Which component of SASE is primarily responsible for inspecting encrypted traffic for threats?

Medium
160

A company is migrating its workloads to a public cloud and wants to ensure it understands the division of security responsibilities. Which model defines the demarcation of security controls between the cloud provider and the customer?

Medium
161

A security architect is designing a data loss prevention (DLP) program for a company that uses Microsoft 365 and a SaaS CRM. The architect must reduce false positives while still detecting sensitive data leaving the environment. Which TWO capabilities should be prioritized? (Choose two.)

Hard
162

Which of the following is a cloud-native security control provided by a cloud service provider to manage user permissions and access to resources?

Easy
163

A security architect at a healthcare provider must design a solution that lets clinicians access patient records from managed laptops and personal tablets without exposing the internal electronic health record (EHR) network. The requirement is that no inbound firewall ports be opened and that access decisions evaluate device posture and user identity on every session. Which solution best meets these requirements?

Medium
164

A security architect for a healthcare provider must ensure that a new patient portal can exchange data with an external partner's system without the two organizations having to share or manage each other's identity credentials. The portal must support SAML assertions, provide centralized session revocation, and allow attribute-based authorization decisions at the relying party. Which of the following should the architect implement?

Medium
165

A security architect at a financial services firm is designing the network for a new containerized trading platform. The platform must enforce Layer 7 policy, provide mutual TLS between all microservices, and eliminate the need to reconfigure each application for cryptographic identity. Which architecture should the architect implement?

Medium
166

A security analyst is reviewing a Kubernetes cluster and wants to ensure that only authorized users can create or modify pods. Which Kubernetes object should be configured to enforce this?

Easy
167

An organization is planning to modernize its cryptographic infrastructure to protect sensitive data for the next 10 years. The security architect must consider future threats from quantum computing. Which TWO quantum-resistant algorithms should the architect prioritize for key encapsulation and digital signatures? (Choose TWO.)

Easy
168

A retail company is designing a new payment processing environment and wants to reduce the scope of its PCI DSS assessment. The architect proposes isolating the cardholder data environment from the rest of the corporate network so that most systems fall outside the audit boundary. Which of the following design approaches best supports this goal?

Easy
169

A software company wants to ensure that every container image deployed to production is free of known critical vulnerabilities and is cryptographically signed by its build pipeline. The security architect must implement controls that verify the signature and vulnerability status before the container runtime starts the image. Which of the following should the architect implement?

Medium
170

A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The organization wants to minimize the impact on application performance and avoid modifying the application code. Which of the following should the architect implement?

Easy
171

A security engineer is hardening a Kubernetes environment. Which THREE of the following are effective controls for securing the cluster? (Select THREE.)

Medium
172

A company is deploying containerized applications on Kubernetes and needs to ensure that only authorized images are run in the cluster. Which Kubernetes resource should be used to enforce policies on what containers can run, including image source restrictions?

Hard
173

During a threat modeling exercise for a new web application, the team identifies that the application uses JWT for authentication. Which vulnerability is most likely if the server does not properly verify the JWT signature?

Hard
174

A financial services firm is designing its identity architecture for a Zero Trust program. Auditors require that authentication strength be continuously evaluated and that a compromised endpoint lose access to sensitive trading applications even after the user has already authenticated. The security architect must select TWO capabilities that directly support continuous, context-aware authorization decisions. (Choose two.)

Hard
175

A software company is designing an internal developer platform where engineers need short-lived credentials to access production databases. The security architect wants to eliminate long-lived static database passwords, bind access to the identity of the calling workload, and automatically revoke credentials when a deployment is removed. Which of the following should the architect implement?

Medium
176

A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?

Medium
177

Which technology is used to discover and control cloud applications, enforce security policies, and provide visibility into cloud usage?

Easy
178

An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?

Medium
179

In a cloud shared responsibility model, which of the following is typically the customer's responsibility for IaaS?

Easy
180

A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)

Medium
181

A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?

Hard
182

A security architect is designing a microsegmentation strategy for a hybrid cloud environment. The organization wants to enforce least-privilege network access between workloads, prevent lateral movement, and maintain visibility into east-west traffic. Which TWO of the following controls are MOST appropriate to achieve these goals? (Choose two.)

Hard
183

A security architect is evaluating a software-defined wide area network (SD-WAN) solution to connect branch offices to cloud services. The architect wants to ensure that traffic from branches to cloud applications is inspected for threats without backhauling all traffic to the data center. Which capability should the architect prioritize?

Easy
184

A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?

Medium
185

A company is modernizing its security operations center and wants to correlate logs from firewalls, endpoints, and cloud services in a single platform that supports long-term retention and custom detection rules. Which technology best fits this requirement?

Easy
186

During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?

Medium
187

A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?

Medium
188

A security architect at a financial services firm must ensure that virtual machine workloads on a private cloud cannot execute unauthorized binaries, even if an attacker gains root access. The solution must enforce policy at the hypervisor layer without relying on agents inside the guest OS. Which of the following should the architect implement?

Medium

Frequently asked questions

What does the Security Architecture domain cover on the CAS-005 exam?
Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.
How many questions are in this domain?
This page lists all 188 Security Architecture questions in the CAS-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
casp-plus CASP-PLUS casp security architecture Practice Questions