QUESTION 1 You’re brought into a project late in the design phase. The company is launching a new customer-facing credit card account portal that will let customers view balances, make payments, update contact information, request replacement cards, and manage account security settings. Engineering says the system is mostly complete and asks you to perform the security architecture review before production. Walk me through how you would approach the review. ANSWER First I would understanding the existing state of the project holisitcally by reviewing the infrastructure as code stacks, understand where and why things were deployed in the way they were, and then jump into meetings with the primary senior technical staff, project managers, and business leaders who are supporting the project to understand the totality of the infrastructure. once i have all of this information I will be in a state to begin looking at things from an attackers perspective, a business and business reputation risk standpoint, and a cost center perspective to see where critical findings are and begin working those first, then work the medium priority findings, and then finally the nice to have issues. this would ensure that the most serious security issues are handled first while not impacting the continuing flow of the project overall. if i was to find an extremely critical issue i would leverage security leadership to ensure the vulnerability or configuration issue is prioritized. once an MVP or prototype product is ready, i would request it be build inside of a bubble in a cloud environment, then request that a third party offensive security team perform a targeted whitebox assessment of the MVP/prototype to ensure we have multiple layers of eyes and hands validating risk and vulnerabilities. QUESTION 2 Engineering proposes the following design: The customer portal sends credit-card numbers to a backend API. The API encrypts the PAN using an application-managed encryption key and stores the encrypted value in a PostgreSQL database. The encryption key is stored as a Kubernetes secret in the same cluster as the application. Developers argue that this is safe because the PAN is encrypted at rest. As the security architect, how would you evaluate this design, and what changes would you recommend? ANSWER First I would look at this from a network and process segmentation perspective. I would want to understand what type of encryption scheme is being implemented for data in transit like the PAN, then I would want to understand how encryption is setup for data at rest and the stateful backups of the dataset as well. once i understand the overall encryption scheme i would begin to explore how the K8s/Kubernetes vault is configured and see if this highly sensitive payment portal is sharing a k8s cluster with less critical services. my primary concern is that all services are hosted out of the same k8s cluster, which means that a lower priority/criticality service could be attacked and then this PAN processing api/backend could be a lateral movement target. i would leverage project documentation, the terraform/iac/source of the project, and also perform a "user drive test" using example accounts and data to see if there are any critical web app vulnerabilities that stand out. once i have all of this information i would then most likely suggest that any systems holding PANs or PII be segmented into their own k8s cluster or microservice environment. QUESTION 3 Your fraud team reports an increase in account takeover against the customer portal. Attackers appear to be using credential stuffing and then changing the victim’s mailing address and phone number before requesting replacement cards. The business does not want to force MFA on every login because they are concerned about customer abandonment and support volume. As the security architect, how would you approach this problem? ANSWER My first instinct would be to understand why a credential stuffing attack is working in the first place. if a brute force style attack is working it tells me that there are not adequate preauth controls in place that will lockout either a non-authenticated session (like with cloudflare or incapsula imperva), or the account itself will go into a softlock mode with a 15-30minute timeout. the lack of MFA/2fa is a problem, and i would try to champion its use and enforcement, but i also understand there are sometimes business needs to downgrade security schemes for the sake of customer retention and not inundating support with additional requests. the other way to add a defense-in-depth focused approach would be to allow the user to only change their phone number or address every 24hrs. if they wish to change both, they need to contact the support line over phone and pass id validation checks. this ensures that an attacker cannot move quickly in the environment to accomplish account takeover, and also provides security staff with the ability to detect and triage suspicious logins (like impossible travel). QUESTION 4 Your company runs heavily in AWS. During an architecture review, you discover that application teams are allowed to create IAM roles and attach policies within their own AWS accounts. They cannot directly assign themselves administrator access, but they can create Lambda functions, ECS tasks, and EC2 instances and assign existing IAM roles to those workloads. How would you evaluate the risk here, and what architectural controls would you recommend? ANSWER I would take a two prong approached: one I would speak with the application team leaders to understand how and what they need to do with iam, if there are any concessions they could make to tighten iam enforcement, and then also verify that they are adhering to IAC fundamentals and steering clear of "click ops" work flows. there may be multiple business and critical mission reasons why the application teams need to be able to design and generator their own IAM roles/policies. once i have a firm understanding of what the application team needs i would begin to explore ways to build a TPI, or two person integrity, model inside of the application team when any IAM or aws account wide changes are made. this puts ownership in the hands of the application team, while also ensuring they dont feel like things are being taken away from them. naturally i would also implement strong cloudwatch rules and centralized log management/siem functionality in these cloud accounts to ensure that if there was a breach or account takeover it would immediately put up a warning flare to the security team and application team. another thing i would request to have run is a tool like "Prowler", which can validate and report on the overall iam and security health of an aws account. once i have all of this information i would report back to security leadership and the ciso with findings, places where the organization could make improvements, and places where we could possibly give the application more room to innovate in a secure and isolated environment. QUESTION 5 Your company wants to integrate with a new fintech vendor that will process some customer payment information and expose APIs back to your environment. The business says the vendor has a SOC 2 Type II report and therefore considers the security review largely complete. As the security architect, how would you assess the vendor and design the integration? ANSWER SOC2 Type 2 is valuable, and points to good overall security controls. however it doesnt provide a true measure of the vendors actual security posture. i would want to understand in fine detail how the vendor would access information on our side, how data at rest and data in transit is secured, what the vendors dr/bcp posture looks like, and also perform an independent investigation into sec 8k filings or other public reporting that could tell me about breaches the vendor may have experienced. some questions i would ask either in person or on a call with the vendor would be when they performed their last red or purpleteam assessment, when they last tested their DR hot or warm site, and how they would interoperate with out organization if there was an incident or breach upstream in their environment. soc2, iso27001, pci-dss, and similar security standards and frameworks are great, point to an organization that is monitoring its own health and security posture, but often miss the mark when uncovering the totality of the vendor/partners security landscape. QUESTION 6 A development organization has hundreds of repositories and deploys several times per day. Security currently requires manual review before production releases, and engineering says this is slowing delivery. You are asked to redesign the security architecture around the software delivery pipeline. How would you approach it? ANSWER i would try to understand if there were places where a version lock could be implemented. while ci/cd is great and can ensure secure/useful code is being pushed, it can often turn into a hat on a hat in regards to upkeep, maintenance, and the amount of work it generates. instead of each and every one of the repositories being included in the overall cicd pipeline, i would ensure that repositories with limited changes are version locked unless there is a medium, high, or critical security finding. often a microservice repo will not need to change for months, so having a human review of that microservice multiple times a day can generate what ammounts to busy work. another thing i would investigate with the development team is where an AI/ML augmented process could be included to alleviate some of the review workload for the team. QUESTION 7 Assume a ransomware operator compromises an employee endpoint, obtains cloud credentials, and begins moving laterally through the environment. The company has backups, but many of those backups are accessible using the same administrative identity structure as production. From an architecture standpoint, what would you change to make the organization more resilient before an incident like this occurs? ANSWER backups, dr warm and hot sites, and even vm replication infrastructure all must utilize a completely isolated and segmentated authentication framework. an example: dr warm and hot sites should not be able to be logged in to by someone with their standard corp network credentials. this is where a tiered access model comes into play. the other thing i would ask about is why an employees endpoint is being used to perform cloud related tasks. the employees endpoint should be a place where they login to a secured development environment, and then can access the cloud environments from there. while this adds to the devops and admins authentication workload, it ensures there are hard network and process segmentation rules in place. it also creates far more work for an attacker who gets an initial foothold on an employees baremetal device. QUESTION 8 A business unit wants to launch a new product on schedule. Your review finds a significant security weakness, but engineering says remediation will delay launch by six weeks. The business argues that the risk is acceptable and wants to proceed. How would you handle that situation as the security architect? ANSWER I would ensure these security weaknesses are well documented, including a "kill chain" of how these security weaknesses could be used together for greater impact. then i would begin working to design a threat detection and anomaly monitoring process around this new product. i completely understand that there are cases where acceptable risk and business tempo outweighs security needs, but there are always avenues of approach to ensure that those risks have adequate monitoring, detection, and response placed around them. another thing i would strive to work towards is ensuring that these security weaknesses are not forgot in the excitement of a new product release; meaning that i would work with project managers to ensure that these security weaknesses are prioritized above feature additions and "nice to have" project milestones. QUESTION 9 An engineering director tells you, “We’re moving to zero trust, so network segmentation is no longer important. Identity is the new perimeter.” How would you respond? ANSWER I would ask leading question like "Well by zero trust, what are you refering to in regards to some of our mission critical systems?", "Is there a chance that we could utilize both zero trust and network segmentation, thereby ensuring we are implementing defense in depth?", and "That sounds really interesting, can you tell me more about the identity perimeter in regards to zero trust?" The reason i would not immediately rebuff what the engineering director is telling me is i might "not know what i dont know", and there may be a business initative or something happening in the organization im not aware of which is making zero trust a really important topic. on the phase of the engineering directors statement, i think he is wrong, but it wouldnt be useful not would it maintain my rapport with the director to call him out on this. often i can sway someone into aligning with my beliefs and using a defense in depth approach by using leading questions, active listening, and also not immediately jumping to conclusions based on the face value of the statement. QUESTION 10 A development team tells you they want to build their own internal encryption library because they need functionality that their cloud provider’s KMS does not expose directly. They plan to use AES-256 for data encryption and RSA for key exchange, and they say the algorithms are industry standard. How would you evaluate that proposal? ANSWER On the face value of that statement, it sounds like an extremely bad idea and not industry standard whatsoever. it would also introduce a lot of tech debt and possible continuity issues in regards to technical personnel leaving or being terminated. i wouldnt immediately call this idea out as bad, instead i would again ask leading questions, appear outwardly interested in the idea so as not to squash a more junior personnel's enthusiasm, and take a lot of notes about the idea. however, i would speak with security leadership about using an industry standard cryptographic library like LibSodium to handle the actual encryption and kex. this is a scenario where i would want to use "kid gloves" with the dev team, gently push them towards a more safe/sane approach that uses a well documented and heavily researched encryption library, and also try to understand how standard cloud provider KMS is not adequate for the teams needs. there is a good chance that this idea was a developers pet project that everything thinks is cool, so immediately shutting that down is not the right initial approach; instead as a senior technical i need to foster that innovation while also ensuring that risky ideas like this are not turned into mission critical business systems. QUESTION 11 You have five minutes with the CIO and CISO. A major modernization program is moving a legacy credit-card servicing platform into AWS. Engineering wants to rehost most of the application unchanged because rewriting it will add roughly a year to the program. Your architecture review has found legacy authentication, broad database permissions, weak service-to-service trust, and several components that cannot support modern security controls without modification. The CIO asks you one question: “Can we safely move this system to the cloud as-is, or do we need to delay the migration?” How would you answer? ANSWER My first answer would be that it depends on the acceptable risk for the organization and this servicing platform. A one year lag time could be extremely detrimental to the business, so moving fast may be on the menu of options. however, i would work with the engineering team to identify the most risky aspects of the platform, ensure those are adequately wrapped in defense in depth and monitor, detect, response infrastructure; then ask that the lift-and-shift/migration be performed into an ephemeral account for one week so a third party offensive security team can perform an assessment to highlight outliers or security issues that might not have been known about. once there is a holistic understanding of the actual security posture of the platform, defense in depth and MDR solutions are in place, then i would give a green light. i would lay this out as a gantt chart so the CIO and rest of c-suite know what to expect with this assessment and implementation. things like broad database permissions, legacy authentication, and not being able to support modern security controls could be triaged and hotfixed during this live assessment in the controlled environment as well. if the CIO needed a once sentence answer: "Yes, but we need to kick tires on this in a controlled and isolated environment to understand the totality of the security issues so we know where are our pain points are."