

Security Architecture and Design
Mock Exam
Course Introduction
Security Architecture and Design explores the foundational concepts, principles, and methodologies involved in creating secure information systems. The course covers the design and implementation of security policies, models, and mechanisms, addressing topics such as secure system lifecycle, trust models, access control, cryptographic integration, and architectural frameworks. Students will examine common threats, vulnerabilities, and controls at both hardware and software levels, as well as best practices for creating robust security architectures that align with organizational goals and regulatory requirements. Through case studies and applied projects, learners gain practical skills in evaluating and designing secure infrastructures in diverse computing environments.
Recommended Textbook
Guide to Firewalls and VPNs 3rd Edition by Michael
E. Whitman

Available Study Resources on Quizplus 10 Chapters
496 Verified Questions
496 Flashcards
Source URL: https://quizplus.com/study-set/2181 Page 2

Chapter 1: Introduction to Information Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43454
Sample Questions
Q1) Responsible for the security and use of a particular set of information.
A)data custodian
B)Trojan horse
C)integrity
D)back door
E)balance
F)worm
G)accuracy
H)data owner
I)confidentiality
Answer: H
Q2) Describe the importance of enabling the safe operation of applications.
Answer: Organizations are under immense pressure to acquire and operate integrated, efficient, and capable information systems.They need to safeguard applications, particularly those that serve as important elements of the infrastructure of the organization, such as operating system platforms, electronic mail (e-mail), instant messaging (IM), and all the other applications that make up the current IT environment.
Q3) The most common Intellectual Property breach is ____________________.
Answer: software piracy
To view all questions and flashcards with answers, click on the resource link above.
Page 3

Chapter 2: Security Policies and Standards
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43455
Sample Questions
Q1) A(n) ____ plan addresses the identification, classification, response, and recovery from an incident.
A) incident response
B) disaster recovery
C) attack profile
D) business impact analysis
Answer: A
Q2) Ensures that critical business functions continue if a catastrophic incident or disaster occurs.
A)managerial guidance SysSP document
B)security training
C)incident response
D)business continuity plan
E)information security policy
F)de jure
G)de facto
H)security blueprint
I)business impact analysis
Answer: D
To view all questions and flashcards with answers, click on the resource link above.
Page 4

Chapter 3: Authenticating Users
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43456
Sample Questions
Q1) A PIN is an example of something you ____.
A) know
B) have
C) are
D) do
Answer: A
Q2) Access controls are defined only using technology. A)True
B)False
Answer: False
Q3) What are the functions that can be used to classify access controls?
Answer: Preventive-help the organization avoid an incident
Deterrent-discourage or deter an incident from occurring
Detective-detect or identify an incident or threat when it occurs
Corrective-remedy a circumstance or mitigate the damage caused during an incident
Recovery-restore operating conditions to normal
Compensating-use alternate controls to resolve shortcomings1
Q4) ____________________ is the act of confirming the identity of a potential user. Answer: Authentication
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Introduction to Firewalls
Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43457
Sample Questions
Q1) A packet-filtering firewall installed on a TCP/IP-based network typically functions at the TCP level.
A)True
B)False
Q2) Port numbers come in two flavors: well-known ports and ____________________ ports.
Q3) Machine that has no unnecessary services, only the bare essentials.
A)PAT and NAT
B)bastion host
C)application proxy
D)extranet
E)header
F)perimeter
G)data
H)port
I)packet filtering
Q4) What are some of the advanced security functions provided by modern firewalls?
Q5) What is a MAC layer firewall?
Q6) Describe stateless packet-filtering firewalls.
Q7) What components are commonly found in a firewall?
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Packet Filtering
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43458
Sample Questions
Q1) The ____ is a structure for organizing Internet names associated with IP addresses.
A) Domain Name System (DNS)
B) Transport Control Protocol (TCP)
C) Hypertext Transfer Protocol (HTTP)
D) Simple Mail Transfer Protocol (SMTP)
Q2) A single bit of information in a TCP packet -the ____________________ flag -indicates if a packet is requesting a connection or a connection has already been established.
Q3) The header field that indicates whether the packet is a fragment is ____.
A) flags
B) options
C) protocol
D) destination IP address
Q4) Describe best practices for testing firewall rules.
Q5) Stateless packet filtering is more secure than stateful packet filtering.
A)True
B)False
Q6) How can a stateful packet filter determine whether a session is beginning or ending?
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Firewall Configuration and Administration
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43459
Sample Questions
Q1) What is a screen saver password? Why is it important?
Q2) In 2003, GASSP was succeeded by ____.
A) GAAP
B) CISSP
C) GAISP
D) GASSPv2
Q3) Describe best practices for adding software updates and patches.
Q4) ____ of frequently accessed resources, such as Web page text and image files, can dramatically speed up the performance of your network because it reduces the load on your Web servers.
A) Hashing
B) Caching
C) Redundancy
D) Load balancing
Q5) If the primary goal of a firewall is to block unauthorized access, the emphasis needs to be on restricting rather than enabling connectivity
A)True
B)False
Q6) What are the GAISP nine Pervasive Principles?
Page 8
To view all questions and flashcards with answers, click on the resource link above.
Chapter 7: Working With Proxy Servers and
Application-Level Firewalls
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43460
Sample Questions
Q1) How should administrators combat buffer overflow?
A) Configure buffers carefully.
B) Update proxy servers frequently.
C) Use only Microsoft products.
D) Limit the use of proxy servers.
Q2) Computer that has two separate network interfaces, one to the external Internet and one to the internal LAN.
A)dual-homed host
B)URL redirection
C)nontransparent proxies
D)log files
E)parameters
F)SOCKS
G)WinGate
H)proxy servers
I)transparent proxies
Q3) How do reverse proxy servers work?
Q4) What is SOCKS?

Page 9
Q5) Describe the pros and cons of blocking URLs with a proxy server.
Q6) How can proxy servers affect performance of the network?
To view all questions and flashcards with answers, click on the resource link above.
Page 10

Chapter 8: Implementing the Bastion Host
Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43461
Sample Questions
Q1) System specifically designed and implemented to withstand attacks.
A)instruction cache
B)log files
C)translation lookaside buffer
D)data cache
E)Demilitarized Zone
F)bastion host
G)UNIX
H)processor speed
I)syslog daemon
Q2) On a UNIX host, you should run a ____ check, a set of software programs that makes sure any software you're running on your system is a trusted program.
A) Security Assessment Tool
B) Baseline Security Analyzer
C) Trusted Computing Base
D) security_patch_check
Q3) Why is it a good idea to disable user accounts on the bastion host?
Q4) Describe the RAM needs of a bastion host.
Q5) Discuss the pros and cons of having more than one bastion host.
Q6) What type of documentation should you keep for your bastion host?
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 9: Encryption - The Foundation for the Virtual
Private
Network
Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/43462
Sample Questions
Q1) ____ was developed by Netscape in 1994 to provide security for online electronic commerce transactions.
A) Secure Hypertext Transfer Protocol (SHTTP)
B) Secure Shell (SSH)
C) Secure Sockets Layer (SSL)
D) Secure Electronic Transactions (SET)
Q2) Historically, attempts to gain unauthorized access to secure communications have used brute force attacks.
A)True
B)False
Q3) ____ was developed as an improvement to DES and uses as many as three keys in succession.
A) Triple DES
B) AES
C) Vernam
D) Rijndael
Q4) In ____________________ cipher conversion, the bit stream is subjected to a Boolean XOR function against some other data stream, typically a key stream.
Q5) What are common implementations of PKI?
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Setting up a Virtual Private Network
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43463
Sample Questions
Q1) Making two connections over a VPN line is called ____.
A) IP Masquerade
B) packet filtering
C) split tunneling
D) split endpoints
Q2) Makes a network accessible to remote users who need dial-in access.
A)encapsulation
B)tunnel
C)client-to-site
D)transport mode
E)gateway
F)private leased lines
G)tunnel mode
H)site-to-site
I)Point-to-Point Tunneling Protocol
Q3) The problem with mesh VPNs is that the requirement that all communications flow into and out of the central router slows down communications.
A)True
B)False
Q4) Describe the hub-and-spoke configuration of a VPN.
To view all questions and flashcards with answers, click on the resource link above. Page 13