Security Architecture Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Architecture flashcards as text
Which security architecture concept requires every access request to be fully validated, regardless of the requester's previous authentication status?
Answer: Complete mediation
Complete mediation requires every access to every object to be checked against access control policy, with no caching of permissions.
In the context of secure hardware, what does a Trusted Platform Module (TPM) primarily provide?
Answer: Secure storage of cryptographic keys and platform integrity measurements
A TPM is a dedicated chip that provides secure key storage, platform integrity attestation via PCRs, and cryptographic functions.
Which approach to system design creates multiple layers of redundant security controls so that failure of one does not result in a breach?
Answer: Defense in depth
Defense in depth implements layered security controls so an attacker must defeat multiple independent mechanisms to succeed.
An application uses a hardware security module (HSM) to perform all cryptographic operations. What is the primary security advantage?
Answer: Private keys never leave the tamper-resistant hardware boundary
HSMs ensure private keys are generated and used inside tamper-resistant hardware, preventing key extraction even by privileged administrators.
Which security architecture pattern uses a single entry and exit point to enforce security policy on all network traffic?
Answer: Choke point
A choke point funnels all traffic through a single controlled gateway, making it easier to monitor and enforce security policies.
The Brewer-Nash (Chinese Wall) model was specifically designed to prevent:
Answer: Conflicts of interest in commercial environments
The Brewer-Nash (Chinese Wall) model prevents analysts from accessing data belonging to competing clients to avoid conflicts of interest.
What security risk is most directly mitigated by using immutable infrastructure (replace rather than patch)?
Answer: Configuration drift and unauthorized changes accumulating over time
Immutable infrastructure eliminates configuration drift by replacing entire instances rather than patching running systems.