Security Architecture & Engineering Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & Engineering flashcards as text
Which security model is primarily designed to prevent unauthorized data disclosure by enforcing confidentiality based on classification labels?
Answer: Bell-LaPadula Confidentiality Model
The Bell-LaPadula model enforces confidentiality by ensuring subjects cannot read data at a higher classification level (no read up) and cannot write to a lower classification level (no write down).
In the context of CAP and the RMF, what does the principle of 'least privilege' require?
Answer: Users receive only the minimum access rights necessary to perform their job functions
Least privilege requires that users, processes, and systems are granted only the minimum permissions necessary to accomplish their authorized tasks, reducing the attack surface.
Which NIST Special Publication provides the catalog of security and privacy controls for federal information systems and organizations?
Answer: NIST SP 800-53
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls that federal agencies select and implement to protect their information systems.
What is the primary purpose of defining an 'authorization boundary' in information system architecture?
Answer: To delineate the scope of the information system for authorization purposes, including all components to be authorized
The authorization boundary identifies the system scope — all hardware, software, firmware, and people within that boundary are subject to the same authorization decision.
Which security architecture principle ensures that no single individual can complete a sensitive or critical process alone?
Answer: Separation of duties
Separation of duties divides critical tasks among multiple individuals so that no one person can carry out a sensitive function alone, reducing fraud and error risk.
What does 'defense in depth' mean as a security architecture strategy?
Answer: Deploying multiple layers of security controls throughout an information system so that failure of one does not compromise overall security
Defense in depth applies multiple, overlapping security controls so that if one layer fails or is bypassed, additional layers continue to provide protection.
What is the primary purpose of a System Security Plan (SSP) within the RMF process?
Answer: To document how security controls are implemented, planned, or inherited for an information system
The SSP describes the system environment, system boundaries, and the security controls in place or planned, serving as the authoritative document for the system's security posture.