Security Architecture & Engineering Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture & Engineering flashcards as text
What does 'non-repudiation' provide in information system security architecture?
Answer: Assurance that an entity cannot later deny having performed a specific action or transaction
Non-repudiation provides proof of origin or delivery of data so that neither sender nor receiver can later deny involvement in a transaction, often implemented via digital signatures.
Which principle in secure design states that the security of a system should not depend on the secrecy of its design or implementation?
Answer: Open design
Open design, a Saltzer and Schroeder principle, holds that security mechanisms should be publicly scrutinizable — security should come from key secrecy, not algorithm or design secrecy.
What is the purpose of 'tailoring' security controls during the RMF Select step?
Answer: Adjusting the baseline controls by applying scoping guidance, adding compensating controls, or specifying parameter values to match system-specific conditions
Tailoring allows organizations to adjust the baseline controls based on organizational policies, risk assessments, and operational requirements while documenting all deviations.
In secure system architecture, what does 'data-at-rest' protection primarily address?
Answer: Encryption and access controls for data stored on physical media, databases, or file systems
Data-at-rest protection focuses on encrypting and controlling access to stored data — on hard drives, SSDs, tapes, or databases — when data is not actively being transmitted or processed.
Which access control model evaluates multiple attributes (user, resource, environment) dynamically to make access decisions?
Answer: Attribute-Based Access Control (ABAC)
ABAC evaluates attributes of the subject, object, and environment at the time of each access request, enabling fine-grained, context-aware access decisions beyond static role assignments.
Under the RMF, what is the role of 'inherited controls' in a system's security architecture?
Answer: Security controls provided and managed by an external entity (common control provider) that the system leverages rather than implementing independently
Inherited controls (common controls) are implemented by an external provider such as a data center or enterprise service and shared across multiple systems, reducing duplication and cost.
What does the 'psychological acceptability' principle in secure system design require?
Answer: Security mechanisms must be designed to be as minimally intrusive as possible so users will comply with them naturally
Psychological acceptability, a Saltzer and Schroeder principle, states that security mechanisms should not make the system harder to use than if they were absent, ensuring users do not circumvent them.