Security Architecture & Engineering Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & Engineering flashcards as text
Which security principle states that a failed security mechanism should deny access rather than allow it?
Answer: Fail-safe defaults
Fail-safe defaults means that when a system or security control fails, it defaults to a secure state — denying access rather than permitting it.
What does the security architecture principle of 'complete mediation' require?
Answer: Every access to every object must be checked against the access control policy each time access is attempted
Complete mediation requires that every access request to every object is validated against access controls each time, with no caching of previous authorization decisions.
In federal security architecture, what is a 'common control' as defined in NIST guidance?
Answer: A security control whose implementation is managed by an external entity and can be inherited by multiple information systems
Common controls are security controls provided by an organizational entity (e.g., a data center team) and inherited by multiple information systems, reducing duplicated implementation effort.
In the Biba Integrity Model, what does the 'simple integrity axiom' (no read down) state?
Answer: A subject cannot read objects at a lower integrity level than its own
The simple integrity axiom prevents a subject from reading data at a lower integrity level, protecting the subject from contamination by less-trusted data.
What is the significance of 'security categorization' as the first step of the RMF for security architecture decisions?
Answer: It determines the potential impact (Low, Moderate, High) of a breach of confidentiality, integrity, or availability, driving control baseline selection
Security categorization using FIPS 199 determines the system's impact level, which in turn determines the appropriate baseline of security controls from NIST SP 800-53B.
Which security architecture concept describes using role assignments rather than individual user identities to determine access rights?
Answer: Role-Based Access Control (RBAC)
RBAC assigns permissions to roles (e.g., 'system administrator') and then assigns users to those roles, simplifying access management in large organizations.
What does the principle of 'economy of mechanism' require in secure system design?
Answer: Keeping security mechanisms as simple and small as possible to reduce the attack surface and ease verification
Economy of mechanism holds that simpler designs are easier to verify, test, and trust — complexity introduces potential for undetected flaws.