Topic 10 Practice Test 2 covers Security Architecture Models for CompTIA Security+ SY0-701 and maps to objective 3.1: Compare and contrast security implications of different architecture models. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
What is a design in which key control, processing, or management functions are concentrated in a central location or service?
- Virtualization
- Cloud shared-responsibility model
- Centralized architecture
- Infrastructure as code (IaC)
Correct Answer: C
Correct Answer
Answer C is correct because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service. This matches the requirement as written. Virtualization can be valid in another context, but it is used for abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.
Incorrect Answers
Answer A is incorrect because Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. The concept is valid, but it does not match this stem. The required function is a design in which key control, processing, or management functions are concentrated in a central location or service, which maps to Centralized architecture.
Answer B is incorrect because Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model. The key mismatch is functional: Centralized architecture addresses a design in which key control, processing, or management functions are concentrated in a central location or service, the need stated by the question.
Answer D is incorrect because Infrastructure as code (IaC) refers to definition and deployment of infrastructure through machine-readable configuration or code. The key mismatch is functional: Centralized architecture addresses a design in which key control, processing, or management functions are concentrated in a central location or service, the need stated by the question.
Question 2
During an architecture-model selection exercise, the team has two independent requirements: (1) separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation; and (2) shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements. Which TWO choices best satisfy those requirements? Choose TWO.
- Scalability
- Real-time operating system (RTOS)
- Risk transference
- Virtualization
- Logical segmentation
Correct Answers: C, E
Correct Answers
Answer C is correct because Risk transference means shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements. One required function is exactly what this option provides. Virtualization may be useful elsewhere, but it is used for abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.
Answer E is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. One required function is exactly what this option provides. Virtualization may be useful elsewhere, but it is used for abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.
Incorrect Answers
Answer A is incorrect because Scalability means the ability of an architecture to handle increased load by adding or expanding resources. The question requires exactly 2 selections: Risk transference, Logical segmentation. This option falls outside that required set. For example, Logical segmentation is required for separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation.
Answer B is incorrect because Real-time operating system (RTOS) means an operating system designed to meet strict timing and deterministic response requirements. The required choices are Risk transference, Logical segmentation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer D is incorrect because Virtualization means abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. Every answer slot must map to a stated requirement. The correct set is Risk transference, Logical segmentation, so this option cannot replace one of those selections.
Question 3
To deploy portable workloads with stronger process isolation than ordinary applications, which security approach should be selected?
- Containerization
- On-premises architecture
- Cloud shared-responsibility model
- Software-defined networking (SDN)
Correct Answer: A
Correct Answer
Answer A is correct because Containerization means operating-system-level isolation that packages applications and dependencies into lightweight containers. That is the function the question is testing. Software-defined networking (SDN) would instead be used for a networking model that separates centralized control logic from packet-forwarding functions.
Incorrect Answers
Answer B is incorrect because On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization. This could be appropriate elsewhere, but the required function is operating-system-level isolation that packages applications and dependencies into lightweight containers; that makes Containerization the precise choice.
Answer C is incorrect because Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model. The question is not asking for this function. It is testing operating-system-level isolation that packages applications and dependencies into lightweight containers, so Containerization is the stronger fit.
Answer D is incorrect because Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions. The concept is valid, but it does not match this stem. The required function is operating-system-level isolation that packages applications and dependencies into lightweight containers, which maps to Containerization.
Question 4
Which term describes network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles?
- Internet of Things (IoT)
- Resilience
- Scalability
- Centralized architecture
Correct Answer: A
Correct Answer
Answer A is correct because Internet of Things (IoT) means network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles. The deciding point is functional fit: this option covers the stated need, while Centralized architecture addresses a design in which key control, processing, or management functions are concentrated in a central location or service.
Incorrect Answers
Answer B is incorrect because Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation. The scenario instead requires network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles, which is why Internet of Things (IoT) is the better answer; this option serves the different function defined above.
Answer C is incorrect because Scalability refers to the ability of an architecture to handle increased load by adding or expanding resources. The key mismatch is functional: Internet of Things (IoT) addresses network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles, the need stated by the question.
Answer D is incorrect because Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service. The scenario instead requires network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles, which is why Internet of Things (IoT) is the better answer; this option serves the different function defined above.
Question 5
An architect working on an architecture-model selection exercise needs one capability that provides separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation and another that provides industrial control and supervisory systems used to monitor or control physical processes. Which TWO selections are the best match? Choose TWO.
- Logical segmentation
- Serverless architecture
- ICS/SCADA
- Software-defined networking (SDN)
- Centralized architecture
Correct Answers: A, C
Correct Answers
Answer A is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. One required function is exactly what this option provides. Serverless architecture may be useful elsewhere, but it is used for a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services.
Answer C is correct because ICS/SCADA means industrial control and supervisory systems used to monitor or control physical processes. One required function is exactly what this option provides. Software-defined networking (SDN) may be useful elsewhere, but it is used for a networking model that separates centralized control logic from packet-forwarding functions.
Incorrect Answers
Answer B is incorrect because Serverless architecture means a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services. Every answer slot must map to a stated requirement. The correct set is Logical segmentation, ICS/SCADA, so this option cannot replace one of those selections.
Answer D is incorrect because Software-defined networking (SDN) means a networking model that separates centralized control logic from packet-forwarding functions. The question requires exactly 2 selections: Logical segmentation, ICS/SCADA. This option falls outside that required set. For example, ICS/SCADA is required for industrial control and supervisory systems used to monitor or control physical processes.
Answer E is incorrect because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service. The required choices are Logical segmentation, ICS/SCADA. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 6
During an architecture-model selection exercise, three requirements must be addressed: (1) abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor; (2) network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles; and (3) architecture designed to minimize service interruption through redundancy and failover. Which THREE choices best satisfy them? Choose THREE.
- Virtualization
- Risk transference
- High availability
- Internet of Things (IoT)
- Scalability
- Decentralized architecture
Correct Answers: A, C, D
Correct Answers
Answer A is correct because Virtualization means abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. The fixed-count item needs this function in the answer set. Decentralized architecture covers a design that distributes control or processing across multiple independent components or locations, a different requirement.
Answer C is correct because High availability means architecture designed to minimize service interruption through redundancy and failover. One required function is exactly what this option provides. Decentralized architecture may be useful elsewhere, but it is used for a design that distributes control or processing across multiple independent components or locations.
Answer D is correct because Internet of Things (IoT) means network-connected embedded devices that often have specialized functions, constrained resources, and long lifecycles. It belongs in the fixed-count answer set because it covers one of the stated requirements. Decentralized architecture instead serves a design that distributes control or processing across multiple independent components or locations and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Risk transference means shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements. The required choices are Virtualization, High availability, Internet of Things (IoT). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Scalability means the ability of an architecture to handle increased load by adding or expanding resources. The required choices are Virtualization, High availability, Internet of Things (IoT). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer F is incorrect because Decentralized architecture means a design that distributes control or processing across multiple independent components or locations. The required choices are Virtualization, High availability, Internet of Things (IoT). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 7
Which term describes separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation?
- On-premises architecture
- Logical segmentation
- Real-time operating system (RTOS)
- Microservices architecture
Correct Answer: B
Correct Answer
Answer B is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. That makes it the best answer here; On-premises architecture addresses systems operated in facilities and infrastructure controlled directly by the organization, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization. That concept can be valid in another scenario, but this question is testing separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation; Logical segmentation therefore fits the requirement more directly.
Answer C is incorrect because Real-time operating system (RTOS) refers to an operating system designed to meet strict timing and deterministic response requirements. The question is not asking for this function. It is testing separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation, so Logical segmentation is the stronger fit.
Answer D is incorrect because Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces. The scenario instead requires separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation, which is why Logical segmentation is the better answer; this option serves the different function defined above.
Question 8
To reduce remote attack paths for highly sensitive systems, which security approach should be selected?
- Virtualization
- ICS/SCADA
- Centralized architecture
- Air-gapped network
Correct Answer: D
Correct Answer
Answer D is correct because Air-gapped network means a network intentionally isolated from other networks through physical separation. This is the precise fit for the scenario. Centralized architecture serves the different purpose of a design in which key control, processing, or management functions are concentrated in a central location or service.
Incorrect Answers
Answer A is incorrect because Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. The concept is valid, but it does not match this stem. The required function is a network intentionally isolated from other networks through physical separation, which maps to Air-gapped network.
Answer B is incorrect because ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes. The question is not asking for this function. It is testing a network intentionally isolated from other networks through physical separation, so Air-gapped network is the stronger fit.
Answer C is incorrect because Centralized architecture refers to a design in which key control, processing, or management functions are concentrated in a central location or service. That concept can be valid in another scenario, but this question is testing a network intentionally isolated from other networks through physical separation; Air-gapped network therefore fits the requirement more directly.
Question 9
The control set for an architecture-model selection exercise must address both division of security duties between a cloud service provider and the customer that varies by service model and architecture designed to minimize service interruption through redundancy and failover. Which TWO choices map directly to those needs? Choose TWO.
- Microservices architecture
- ICS/SCADA
- High availability
- Cloud shared-responsibility model
- Centralized architecture
Correct Answers: C, D
Correct Answers
Answer C is correct because High availability means architecture designed to minimize service interruption through redundancy and failover. This selection maps directly to one of the named needs. ICS/SCADA addresses industrial control and supervisory systems used to monitor or control physical processes, so it does not satisfy the same slot.
Answer D is correct because Cloud shared-responsibility model means a division of security duties between a cloud service provider and the customer that varies by service model. One required function is exactly what this option provides. ICS/SCADA may be useful elsewhere, but it is used for industrial control and supervisory systems used to monitor or control physical processes.
Incorrect Answers
Answer A is incorrect because Microservices architecture means an application model composed of small independently deployable services communicating through defined interfaces. The scenario calls for High availability, Cloud shared-responsibility model. Selecting this option would leave one of those required functions uncovered.
Answer B is incorrect because ICS/SCADA means industrial control and supervisory systems used to monitor or control physical processes. The fixed-count answer set is High availability, Cloud shared-responsibility model; this option does not fill one of those named functions.
Answer E is incorrect because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service. The fixed-count answer set is High availability, Cloud shared-responsibility model; this option does not fill one of those named functions.
Question 10
The control set for an architecture-model selection exercise must address both operating-system-level isolation that packages applications and dependencies into lightweight containers and ability of an architecture to handle increased load by adding or expanding resources. Which TWO choices map directly to those needs? Choose TWO.
- Infrastructure as code (IaC)
- Scalability
- High availability
- Real-time operating system (RTOS)
- Containerization
Correct Answers: B, E
Correct Answers
Answer B is correct because Scalability means the ability of an architecture to handle increased load by adding or expanding resources. The fixed-count item needs this function in the answer set. Real-time operating system (RTOS) covers an operating system designed to meet strict timing and deterministic response requirements, a different requirement.
Answer E is correct because Containerization means operating-system-level isolation that packages applications and dependencies into lightweight containers. This selection maps directly to one of the named needs. Infrastructure as code (IaC) addresses definition and deployment of infrastructure through machine-readable configuration or code, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Infrastructure as code (IaC) means definition and deployment of infrastructure through machine-readable configuration or code. The question requires exactly 2 selections: Scalability, Containerization. This option falls outside that required set. For example, Scalability is required for the ability of an architecture to handle increased load by adding or expanding resources.
Answer C is incorrect because High availability means architecture designed to minimize service interruption through redundancy and failover. The question requires exactly 2 selections: Scalability, Containerization. This option falls outside that required set. For example, Containerization is required for operating-system-level isolation that packages applications and dependencies into lightweight containers.
Answer D is incorrect because Real-time operating system (RTOS) means an operating system designed to meet strict timing and deterministic response requirements. Every answer slot must map to a stated requirement. The correct set is Scalability, Containerization, so this option cannot replace one of those selections.
Question 11
Which term describes industrial control and supervisory systems used to monitor or control physical processes?
- Software-defined networking (SDN)
- On-premises architecture
- Risk transference
- ICS/SCADA
Correct Answer: D
Correct Answer
Answer D is correct because ICS/SCADA means industrial control and supervisory systems used to monitor or control physical processes. The requirement maps directly to this function, whereas On-premises architecture is aimed at systems operated in facilities and infrastructure controlled directly by the organization.
Incorrect Answers
Answer A is incorrect because Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions. This could be appropriate elsewhere, but the required function is industrial control and supervisory systems used to monitor or control physical processes; that makes ICS/SCADA the precise choice.
Answer B is incorrect because On-premises architecture refers to systems operated in facilities and infrastructure controlled directly by the organization. The key mismatch is functional: ICS/SCADA addresses industrial control and supervisory systems used to monitor or control physical processes, the need stated by the question.
Answer C is incorrect because Risk transference refers to shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements. The question is not asking for this function. It is testing industrial control and supervisory systems used to monitor or control physical processes, so ICS/SCADA is the stronger fit.
Question 12
Which term describes systems operated in facilities and infrastructure controlled directly by the organization?
- On-premises architecture
- Decentralized architecture
- Software-defined networking (SDN)
- High availability
Correct Answer: A
Correct Answer
Answer A is correct because On-premises architecture means systems operated in facilities and infrastructure controlled directly by the organization. This is the precise fit for the scenario. Decentralized architecture serves the different purpose of a design that distributes control or processing across multiple independent components or locations.
Incorrect Answers
Answer B is incorrect because Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations. That concept can be valid in another scenario, but this question is testing systems operated in facilities and infrastructure controlled directly by the organization; On-premises architecture therefore fits the requirement more directly.
Answer C is incorrect because Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions. The scenario instead requires systems operated in facilities and infrastructure controlled directly by the organization, which is why On-premises architecture is the better answer; this option serves the different function defined above.
Answer D is incorrect because High availability refers to architecture designed to minimize service interruption through redundancy and failover. The scenario instead requires systems operated in facilities and infrastructure controlled directly by the organization, which is why On-premises architecture is the better answer; this option serves the different function defined above.
Question 13
What is an application model composed of small independently deployable services communicating through defined interfaces?
- High availability
- Microservices architecture
- Resilience
- Decentralized architecture
Correct Answer: B
Correct Answer
Answer B is correct because Microservices architecture means an application model composed of small independently deployable services communicating through defined interfaces. This matches the requirement as written. Resilience can be valid in another context, but it is used for the ability of a system or organization to withstand disruption and recover acceptable operation.
Incorrect Answers
Answer A is incorrect because High availability refers to architecture designed to minimize service interruption through redundancy and failover. The scenario instead requires an application model composed of small independently deployable services communicating through defined interfaces, which is why Microservices architecture is the better answer; this option serves the different function defined above.
Answer C is incorrect because Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation. This could be appropriate elsewhere, but the required function is an application model composed of small independently deployable services communicating through defined interfaces; that makes Microservices architecture the precise choice.
Answer D is incorrect because Decentralized architecture refers to a design that distributes control or processing across multiple independent components or locations. This could be appropriate elsewhere, but the required function is an application model composed of small independently deployable services communicating through defined interfaces; that makes Microservices architecture the precise choice.
Question 14
To create security zones while sharing underlying infrastructure, which security approach should be selected?
- Logical segmentation
- Serverless architecture
- Microservices architecture
- ICS/SCADA
Correct Answer: A
Correct Answer
Answer A is correct because Logical segmentation means separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. This matches the requirement as written. ICS/SCADA can be valid in another context, but it is used for industrial control and supervisory systems used to monitor or control physical processes.
Incorrect Answers
Answer B is incorrect because Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services. The key mismatch is functional: Logical segmentation addresses separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation, the need stated by the question.
Answer C is incorrect because Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces. The question is not asking for this function. It is testing separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation, so Logical segmentation is the stronger fit.
Answer D is incorrect because ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes. The scenario instead requires separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation, which is why Logical segmentation is the better answer; this option serves the different function defined above.
Question 15
Which term describes operating-system-level isolation that packages applications and dependencies into lightweight containers?
- Logical segmentation
- Cloud shared-responsibility model
- Containerization
- Microservices architecture
Correct Answer: C
Correct Answer
Answer C is correct because Containerization means operating-system-level isolation that packages applications and dependencies into lightweight containers. The requirement maps directly to this function, whereas Cloud shared-responsibility model is aimed at a division of security duties between a cloud service provider and the customer that varies by service model.
Incorrect Answers
Answer A is incorrect because Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. That concept can be valid in another scenario, but this question is testing operating-system-level isolation that packages applications and dependencies into lightweight containers; Containerization therefore fits the requirement more directly.
Answer B is incorrect because Cloud shared-responsibility model refers to a division of security duties between a cloud service provider and the customer that varies by service model. That concept can be valid in another scenario, but this question is testing operating-system-level isolation that packages applications and dependencies into lightweight containers; Containerization therefore fits the requirement more directly.
Answer D is incorrect because Microservices architecture refers to an application model composed of small independently deployable services communicating through defined interfaces. The concept is valid, but it does not match this stem. The required function is operating-system-level isolation that packages applications and dependencies into lightweight containers, which maps to Containerization.
Question 16
What is the ability of an architecture to handle increased load by adding or expanding resources?
- Logical segmentation
- Scalability
- Software-defined networking (SDN)
- Virtualization
Correct Answer: B
Correct Answer
Answer B is correct because Scalability means the ability of an architecture to handle increased load by adding or expanding resources. That makes it the best answer here; Software-defined networking (SDN) addresses a networking model that separates centralized control logic from packet-forwarding functions, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Logical segmentation refers to separation of systems through technologies such as VLANs, routing, firewalls, or access policies rather than physical separation. That concept can be valid in another scenario, but this question is testing the ability of an architecture to handle increased load by adding or expanding resources; Scalability therefore fits the requirement more directly.
Answer C is incorrect because Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions. The question is not asking for this function. It is testing the ability of an architecture to handle increased load by adding or expanding resources, so Scalability is the stronger fit.
Answer D is incorrect because Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. The question is not asking for this function. It is testing the ability of an architecture to handle increased load by adding or expanding resources, so Scalability is the stronger fit.
Question 17
The control set for an architecture-model selection exercise must address both design in which key control, processing, or management functions are concentrated in a central location or service and abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. Which TWO choices map directly to those needs? Choose TWO.
- Centralized architecture
- Virtualization
- Risk transference
- Air-gapped network
- Infrastructure as code (IaC)
Correct Answers: A, B
Correct Answers
Answer A is correct because Centralized architecture means a design in which key control, processing, or management functions are concentrated in a central location or service. The fixed-count item needs this function in the answer set. Infrastructure as code (IaC) covers definition and deployment of infrastructure through machine-readable configuration or code, a different requirement.
Answer B is correct because Virtualization means abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. This selection maps directly to one of the named needs. Air-gapped network addresses a network intentionally isolated from other networks through physical separation, so it does not satisfy the same slot.
Incorrect Answers
Answer C is incorrect because Risk transference means shifting some financial or operational consequences of risk to another party through contracts, insurance, or service arrangements. Every answer slot must map to a stated requirement. The correct set is Centralized architecture, Virtualization, so this option cannot replace one of those selections.
Answer D is incorrect because Air-gapped network means a network intentionally isolated from other networks through physical separation. The scenario calls for Centralized architecture, Virtualization. Selecting this option would leave one of those required functions uncovered. For example, Virtualization is required for abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor.
Answer E is incorrect because Infrastructure as code (IaC) means definition and deployment of infrastructure through machine-readable configuration or code. Every answer slot must map to a stated requirement. The correct set is Centralized architecture, Virtualization, so this option cannot replace one of those selections.
Question 18
Which division of security duties between a cloud service provider and the customer varies by service model?
- Software-defined networking (SDN)
- Infrastructure as code (IaC)
- Cloud shared-responsibility model
- Containerization
Correct Answer: C
Correct Answer
Answer C is correct because Cloud shared-responsibility model means a division of security duties between a cloud service provider and the customer that varies by service model. The deciding point is functional fit: this option covers the stated need, while Infrastructure as code (IaC) addresses definition and deployment of infrastructure through machine-readable configuration or code.
Incorrect Answers
Answer A is incorrect because Software-defined networking (SDN) refers to a networking model that separates centralized control logic from packet-forwarding functions. The question is not asking for this function. It is testing a division of security duties between a cloud service provider and the customer that varies by service model, so Cloud shared-responsibility model is the stronger fit.
Answer B is incorrect because Infrastructure as code (IaC) refers to definition and deployment of infrastructure through machine-readable configuration or code. That concept can be valid in another scenario, but this question is testing a division of security duties between a cloud service provider and the customer that varies by service model; Cloud shared-responsibility model therefore fits the requirement more directly.
Answer D is incorrect because Containerization refers to operating-system-level isolation that packages applications and dependencies into lightweight containers. The key mismatch is functional: Cloud shared-responsibility model addresses a division of security duties between a cloud service provider and the customer that varies by service model, the need stated by the question.
Question 19
To support embedded or industrial workloads where predictable timing is critical, which security approach should be selected?
- ICS/SCADA
- Real-time operating system (RTOS)
- High availability
- Resilience
Correct Answer: B
Correct Answer
Answer B is correct because Real-time operating system (RTOS) means an operating system designed to meet strict timing and deterministic response requirements. The requirement maps directly to this function, whereas High availability is aimed at architecture designed to minimize service interruption through redundancy and failover.
Incorrect Answers
Answer A is incorrect because ICS/SCADA refers to industrial control and supervisory systems used to monitor or control physical processes. The question is not asking for this function. It is testing an operating system designed to meet strict timing and deterministic response requirements, so Real-time operating system (RTOS) is the stronger fit.
Answer C is incorrect because High availability refers to architecture designed to minimize service interruption through redundancy and failover. The key mismatch is functional: Real-time operating system (RTOS) addresses an operating system designed to meet strict timing and deterministic response requirements, the need stated by the question.
Answer D is incorrect because Resilience refers to the ability of a system or organization to withstand disruption and recover acceptable operation. This could be appropriate elsewhere, but the required function is an operating system designed to meet strict timing and deterministic response requirements; that makes Real-time operating system (RTOS) the precise choice.
Question 20
To segment application functionality and scale components independently, which security approach should be selected?
- Serverless architecture
- High availability
- Virtualization
- Microservices architecture
Correct Answer: D
Correct Answer
Answer D is correct because Microservices architecture means an application model composed of small independently deployable services communicating through defined interfaces. The requirement maps directly to this function, whereas High availability is aimed at architecture designed to minimize service interruption through redundancy and failover.
Incorrect Answers
Answer A is incorrect because Serverless architecture refers to a cloud execution model where the provider manages underlying server infrastructure and customers deploy functions or services. That concept can be valid in another scenario, but this question is testing an application model composed of small independently deployable services communicating through defined interfaces; Microservices architecture therefore fits the requirement more directly.
Answer B is incorrect because High availability refers to architecture designed to minimize service interruption through redundancy and failover. That concept can be valid in another scenario, but this question is testing an application model composed of small independently deployable services communicating through defined interfaces; Microservices architecture therefore fits the requirement more directly.
Answer C is incorrect because Virtualization refers to abstraction that allows multiple virtual systems to share physical compute resources through a hypervisor. The scenario instead requires an application model composed of small independently deployable services communicating through defined interfaces, which is why Microservices architecture is the better answer; this option serves the different function defined above.