← All CISSP Flashcard Decks

Security Architecture Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Architecture flashcards as text
  1. Which security model uses a lattice structure to define information flow between security levels?

    Answer: Bell-LaPadula model

    Bell-LaPadula uses a lattice of security classifications to enforce mandatory access controls based on confidentiality.

  2. A microkernel architecture improves security primarily by:

    Answer: Minimizing the amount of code running in the most privileged mode

    Microkernels keep the kernel minimal, moving services to user space to reduce the attack surface of privileged code.

  3. Which concept describes an architecture where processing occurs at the network edge rather than centralized data centers?

    Answer: Edge computing

    Edge computing moves compute resources closer to data sources, reducing latency and centralization risks.

  4. The principle of 'open design' in security architecture means:

    Answer: System security should not depend on the secrecy of its design

    Open design means the security of a system should not rely on keeping its design secret — only keys/credentials should be secret.

  5. In Common Criteria, a Security Target (ST) is best described as:

    Answer: A document specifying the security claims for a specific product under evaluation

    A Security Target details the specific security properties and claims for the product being evaluated, often based on a Protection Profile.

  6. Which of the following attacks targets the hypervisor in a virtualized environment?

    Answer: Hyperjacking

    Hyperjacking involves compromising or replacing the hypervisor to gain control over all guest virtual machines.

  7. A security architect wants to ensure that no single administrator can make unauthorized changes to the system undetected. Which control best satisfies this?

    Answer: Dual control / two-person integrity

    Dual control (two-person integrity) requires two authorized individuals to perform sensitive actions, preventing unilateral unauthorized changes.