← All CISSP Flashcard Decks

Security Architecture Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Architecture flashcards as text
  1. Which Evaluation Assurance Level (EAL) in Common Criteria represents 'structurally tested' and is the most common for commercial products seeking formal evaluation?

    Answer: EAL4

    EAL4 (methodically designed, tested, and reviewed) is the highest level typically economically feasible for commercial products.

  2. A covert channel in a secure system is best described as:

    Answer: A communication path that was not intended for information transfer but can leak data

    Covert channels exploit unintended communication paths — such as timing or storage — to exfiltrate information in violation of security policy.

  3. In a service-oriented architecture (SOA), which component is primarily responsible for routing messages between services and enforcing security policies?

    Answer: API gateway

    An API gateway enforces authentication, authorization, rate limiting, and other security policies for services in an SOA or microservices environment.

  4. Which threat modeling methodology uses attack trees to enumerate potential attack paths against a system?

    Answer: Attack tree analysis

    Attack tree analysis visually represents attack paths as a tree structure, with the root being the attacker's goal and leaves being specific attack methods.

  5. What is the primary purpose of a security architecture review board?

    Answer: To ensure new systems and changes align with the enterprise security architecture

    A security architecture review board evaluates proposed systems and changes against established architectural standards before implementation.

  6. Which security model defines a formal state machine and requires that the system always transitions to a secure state?

    Answer: State machine model

    The State Machine model defines all allowable system states and ensures every transition moves the system from one secure state to another.

  7. A security architect is designing a system where users can perform actions but cannot grant those permissions to others. Which access control property does this implement?

    Answer: Attenuation of privilege

    Attenuation of privilege (also called the principle of attenuation) ensures subjects cannot grant permissions greater than or equal to their own to others.