📖 Tier 1: Prepare & Study Guide ✓ 100% Solved with Rationales

Cloud Infrastructure, Zero Trust & ISO 27001 Compliance (Computer Science) Solved Questions & Notes (2026) - Apex Rankers

General Competitive Exams > Computer Science > Cloud Infrastructure, Zero Trust & ISO 27001 Compliance

50 Total Solved Questions
~75 mins Estimated Reading Time
1 Subject Areas / Chapters
Select Topic Area / Chapter: Click any section below to switch questions

Cloud Infrastructure, Zero Trust & ISO 27001 Compliance

100%
Showing 25 of 50 (50%)
🎯 Practice
Jump:
Q. 1 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Trusting all internal LAN traffic without requiring passwords or authentication
B
Allowing any user to access the core database without access logs
C
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
D
Eliminating all firewalls and identity management systems
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 2 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, what is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Allowing any user to access the core database without access logs
B
Eliminating all firewalls and identity management systems
C
Trusting all internal LAN traffic without requiring passwords or authentication
D
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 3 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
B
Eliminating all firewalls and identity management systems
C
Trusting all internal LAN traffic without requiring passwords or authentication
D
Allowing any user to access the core database without access logs
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 4 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Trusting all internal LAN traffic without requiring passwords or authentication
B
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
C
Allowing any user to access the core database without access logs
D
Eliminating all firewalls and identity management systems
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 5 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, what is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Allowing any user to access the core database without access logs
B
Eliminating all firewalls and identity management systems
C
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
D
Trusting all internal LAN traffic without requiring passwords or authentication
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 6 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under SOC operations and NIST incident response guidelines: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Eliminating all firewalls and identity management systems
B
Trusting all internal LAN traffic without requiring passwords or authentication
C
Allowing any user to access the core database without access logs
D
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 7 Computer Aptitude Test
Difficulty: medium (1 Mark)
Which architecture best delivers zero-trust security when considering: what is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
B
Trusting all internal LAN traffic without requiring passwords or authentication
C
Allowing any user to access the core database without access logs
D
Eliminating all firewalls and identity management systems
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 8 Computer Aptitude Test
Difficulty: hard (1 Mark)
During enterprise disaster recovery and business continuity planning: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Allowing any user to access the core database without access logs
B
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
C
Eliminating all firewalls and identity management systems
D
Trusting all internal LAN traffic without requiring passwords or authentication
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 9 Computer Aptitude Test
Difficulty: medium (1 Mark)
In cryptographic infrastructure and public key management: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Eliminating all firewalls and identity management systems
B
Trusting all internal LAN traffic without requiring passwords or authentication
C
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
D
Allowing any user to access the core database without access logs
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 10 Computer Aptitude Test
Difficulty: hard (1 Mark)
From an IT operations and ISO/IEC 27001 compliance viewpoint: What is the foundational security philosophy of the Zero Trust Architecture (NIST SP 800-207)?
A
Trusting all internal LAN traffic without requiring passwords or authentication
B
Allowing any user to access the core database without access logs
C
Eliminating all firewalls and identity management systems
D
Never Trust, Always Verify: strictly authenticating and authorizing every user, device, and network transaction continuously regardless of network location
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
Zero Trust eliminates implicit trust based on network perimeter, mandating continuous micro-segmentation, MFA, and least-privilege access verification.
Q. 11 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
B
An antivirus program installed on a single home laptop
C
A database of marketing contacts for sending promotional SMS messages
D
A collection of computer hardware manuals stored in a library
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 12 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A database of marketing contacts for sending promotional SMS messages
B
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
C
A collection of computer hardware manuals stored in a library
D
An antivirus program installed on a single home laptop
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 13 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A collection of computer hardware manuals stored in a library
B
An antivirus program installed on a single home laptop
C
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
D
A database of marketing contacts for sending promotional SMS messages
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 14 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
An antivirus program installed on a single home laptop
B
A database of marketing contacts for sending promotional SMS messages
C
A collection of computer hardware manuals stored in a library
D
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 15 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
B
A database of marketing contacts for sending promotional SMS messages
C
A collection of computer hardware manuals stored in a library
D
An antivirus program installed on a single home laptop
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 16 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under SOC operations and NIST incident response guidelines: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A collection of computer hardware manuals stored in a library
B
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
C
An antivirus program installed on a single home laptop
D
A database of marketing contacts for sending promotional SMS messages
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 17 Computer Aptitude Test
Difficulty: medium (1 Mark)
Which architecture best delivers zero-trust security when considering: under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
An antivirus program installed on a single home laptop
B
A database of marketing contacts for sending promotional SMS messages
C
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
D
A collection of computer hardware manuals stored in a library
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 18 Computer Aptitude Test
Difficulty: hard (1 Mark)
During enterprise disaster recovery and business continuity planning: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A database of marketing contacts for sending promotional SMS messages
B
A collection of computer hardware manuals stored in a library
C
An antivirus program installed on a single home laptop
D
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 19 Computer Aptitude Test
Difficulty: medium (1 Mark)
In cryptographic infrastructure and public key management: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
B
A collection of computer hardware manuals stored in a library
C
An antivirus program installed on a single home laptop
D
A database of marketing contacts for sending promotional SMS messages
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 20 Computer Aptitude Test
Difficulty: hard (1 Mark)
From an IT operations and ISO/IEC 27001 compliance viewpoint: Under ISO/IEC 27001, what is an Information Security Management System (ISMS)?
A
An antivirus program installed on a single home laptop
B
A systematic management framework of policies, procedures, risk assessments, and technical controls to protect organizational information assets
✓ Correct
C
A database of marketing contacts for sending promotional SMS messages
D
A collection of computer hardware manuals stored in a library
💡 Step-by-Step Explanation & Concept Rationale
ISO 27001 ISMS provides holistic governance encompassing risk assessment, access control, cryptography, business continuity, and compliance.
Q. 21 Computer Aptitude Test
Difficulty: medium (1 Mark)
In enterprise network architecture: In enterprise Public Key Infrastructure (PKI) and asymmetric cryptography, how is data confidentiality and non-repudiation achieved?
A
Using the same 4-digit PIN code for all company servers
B
Storing user passwords in clear unencrypted plain text files
C
Encrypting with the recipient public key for confidentiality, and signing with the sender private key for non-repudiation and authentication
✓ Correct
D
Sharing private keys publicly on social media websites
💡 Step-by-Step Explanation & Concept Rationale
Asymmetric PKI uses mathematically linked public-private key pairs to ensure secure end-to-end data encryption, digital signatures, and identity integrity.
Q. 22 Computer Aptitude Test
Difficulty: hard (1 Mark)
Under financial sector cybersecurity and IT governance frameworks, in enterprise Public Key Infrastructure (PKI) and asymmetric cryptography, how is data confidentiality and non-repudiation achieved?
A
Storing user passwords in clear unencrypted plain text files
B
Sharing private keys publicly on social media websites
C
Using the same 4-digit PIN code for all company servers
D
Encrypting with the recipient public key for confidentiality, and signing with the sender private key for non-repudiation and authentication
✓ Correct
💡 Step-by-Step Explanation & Concept Rationale
Asymmetric PKI uses mathematically linked public-private key pairs to ensure secure end-to-end data encryption, digital signatures, and identity integrity.
Q. 23 Computer Aptitude Test
Difficulty: hard (1 Mark)
A Joint Director (IS&TD) overseeing network infrastructure evaluates: In enterprise Public Key Infrastructure (PKI) and asymmetric cryptography, how is data confidentiality and non-repudiation achieved?
A
Encrypting with the recipient public key for confidentiality, and signing with the sender private key for non-repudiation and authentication
✓ Correct
B
Sharing private keys publicly on social media websites
C
Using the same 4-digit PIN code for all company servers
D
Storing user passwords in clear unencrypted plain text files
💡 Step-by-Step Explanation & Concept Rationale
Asymmetric PKI uses mathematically linked public-private key pairs to ensure secure end-to-end data encryption, digital signatures, and identity integrity.
Q. 24 Computer Aptitude Test
Difficulty: medium (1 Mark)
Regarding Cisco/Juniper enterprise routing and switching standards: In enterprise Public Key Infrastructure (PKI) and asymmetric cryptography, how is data confidentiality and non-repudiation achieved?
A
Using the same 4-digit PIN code for all company servers
B
Encrypting with the recipient public key for confidentiality, and signing with the sender private key for non-repudiation and authentication
✓ Correct
C
Storing user passwords in clear unencrypted plain text files
D
Sharing private keys publicly on social media websites
💡 Step-by-Step Explanation & Concept Rationale
Asymmetric PKI uses mathematically linked public-private key pairs to ensure secure end-to-end data encryption, digital signatures, and identity integrity.
Q. 25 Computer Aptitude Test
Difficulty: hard (1 Mark)
In next-generation firewall and perimeter defense engineering, in enterprise Public Key Infrastructure (PKI) and asymmetric cryptography, how is data confidentiality and non-repudiation achieved?
A
Storing user passwords in clear unencrypted plain text files
B
Sharing private keys publicly on social media websites
C
Encrypting with the recipient public key for confidentiality, and signing with the sender private key for non-repudiation and authentication
✓ Correct
D
Using the same 4-digit PIN code for all company servers
💡 Step-by-Step Explanation & Concept Rationale
Asymmetric PKI uses mathematically linked public-private key pairs to ensure secure end-to-end data encryption, digital signatures, and identity integrity.
Study Stream Progress: Showing 25 of 50 Questions (50%)
Jump to:

Ready to Test Your Retention & Speed?

Now that you have reviewed the study questions and rationales, test yourself in our interactive 1-by-1 practice engine or take the full official timed mock exam.