1 of 15
Question 1 of 10 · Governance, Risk, and Compliance
What is subprocessor risk?
Subprocessors are your vendor's vendors; their handling of your data is a fourth-party risk.
Question 2 of 10 · Security Architecture
Which component enforces access decisions in a zero trust model?
The PEP enforces decisions made by the PDP based on policy and context.
Question 3 of 10 · Security Engineering
Which post-quantum concern should influence cryptographic engineering decisions now?
Attackers may store encrypted data to decrypt once quantum computing matures, so crypto agility matters.
Question 4 of 10 · Security Operations
What does a SIEM primarily do in security operations?
SIEMs aggregate and correlate log data to detect and alert.
Question 5 of 10 · Governance, Risk, and Compliance
What does data classification drive?
Classification sets proportionate handling and protection.
Question 6 of 10 · Security Architecture
What does an API gateway provide in a secure architecture?
Gateways enforce authentication, throttling and routing for APIs.
Question 7 of 10 · Security Engineering
Which engineering choice improves resilience of authentication services?
Redundancy keeps authentication available during failures.
Question 8 of 10 · Security Operations
What does correlation across data sources in a SIEM enable?
Correlation links events across sources to reveal attacks.
Question 9 of 10 · Governance, Risk, and Compliance
Which is a key element of third-party risk management?
Ongoing assessment, not just at onboarding, manages third-party risk.
Question 10 of 10 · Security Architecture
What is the benefit of microsegmentation over a flat network?
Microsegmentation isolates workloads, containing compromise.
0 of 10
Governance, Risk, and Compliance
Security Architecture
Security Engineering
Security Operations