iSAQB Certified Professional for Software Architecture (CPSA) Exam — Questions and Answers
Question 1: In microservices architecture, an API Gateway primarily serves which function?
- Managing database schema migrations across services
- Replacing the need for service-to-service communication
- Acting as a single entry point that routes, aggregates, and cross-cuts concerns for client requests (Correct answer)
- Persisting service configuration in a central database
Correct answer: Acting as a single entry point that routes, aggregates, and cross-cuts concerns for client requests
An API Gateway consolidates routing, authentication, rate limiting, and response aggregation so clients interact with one endpoint instead of many services.
Question 2: What is the PRIMARY benefit of applying the DRY (Don't Repeat Yourself) principle?
- Better user interface responsiveness
- Improved runtime execution speed
- Reduced risk of inconsistency when changing logic in one place (Correct answer)
- Smaller binary file sizes
Correct answer: Reduced risk of inconsistency when changing logic in one place
DRY reduces duplication so that when logic must change, it is updated in exactly one place, eliminating the risk of inconsistent copies.
Question 3: Which quality attribute is MOST relevant when a system must continue operating correctly even if one of its microservices fails?
- Usability
- Portability
- Maintainability
- Reliability — specifically fault tolerance (Correct answer)
Correct answer: Reliability — specifically fault tolerance
Fault tolerance, a sub-characteristic of Reliability, ensures the system continues to operate correctly despite component failures.
Question 4: Which scenario best illustrates a violation of the 'stable dependencies' principle?
- A test module that depends on application modules under test
- A logging framework that depends only on standard library interfaces
- A utility library that has no dependencies on any other module
- A frequently changing UI module that is depended upon by a stable core domain module (Correct answer)
Correct answer: A frequently changing UI module that is depended upon by a stable core domain module
Stable dependencies requires that stable (less frequently changed) modules should not depend on volatile (frequently changed) modules; a stable domain depending on a volatile UI violates this.
Question 5: When securing inter-service communication in a microservices system, which cross-cutting mechanism provides mutual authentication at the transport layer?
- API key rotation
- HMAC request signing
- Mutual TLS (mTLS) (Correct answer)
- OAuth 2.0 authorization code flow
Correct answer: Mutual TLS (mTLS)
mTLS requires both client and server to present certificates, ensuring that only authenticated services can communicate with each other.
Question 6: You are documenting a building block for other teams to use. What information is essential to include in the black-box description?
- The specific database schema tables it directly manipulates.
- Its public interfaces, responsibilities, and required quality attributes. (Correct answer)
- The internal algorithms and private helper methods used.
- The hierarchical decomposition into smaller, internal building blocks.
Correct answer: Its public interfaces, responsibilities, and required quality attributes.
A black-box description defines a building block from an external perspective, focusing on what it does, not how it does it. This includes its public interfaces (the 'how to use it'), its responsibilities (the 'what it does'), and any quality attributes (e.g., performance guarantees) that consumers can expect. Internal implementation details are part of the white-box view.
Question 7: A 'black box' perspective on a building block means that:
- Only the block's interface and behavior are visible, not its internals (Correct answer)
- The block processes encrypted data
- The block has no external dependencies
- The block is implemented in an unreadable compiled language
Correct answer: Only the block's interface and behavior are visible, not its internals
A black box view exposes only what a block does (its interface and behavior) without revealing how it does it internally.
Question 8: In a layered (n-tier) architecture, what rule governs the direction of dependencies between layers?
- Each layer can only communicate with non-adjacent layers
- The presentation layer directly accesses the data layer for performance
- Dependencies are bidirectional to allow for efficient communication
- Higher layers may only depend on lower layers, never the reverse (Correct answer)
Correct answer: Higher layers may only depend on lower layers, never the reverse
The strict layering rule dictates that each layer only depends on the layer directly below it, preventing upward dependencies and promoting loose coupling.
Question 9: A software architect proposes using a shared exception hierarchy and a common error-handling framework. This addresses which architectural quality?
- Performance at the hardware level
- Consistency and maintainability across the codebase (Correct answer)
- Scalability of the data store
- Portability to different cloud providers
Correct answer: Consistency and maintainability across the codebase
A common exception hierarchy and error-handling framework reduce divergent error-handling patterns, improving consistency and long-term maintainability.
Question 10: Which of the following BEST describes the concept of 'information hiding' in building block design?
- Restricting database read permissions
- Removing debug logging from production
- Concealing implementation details behind a stable interface (Correct answer)
- Encrypting data at rest
Correct answer: Concealing implementation details behind a stable interface
Information hiding means implementation decisions are concealed behind an interface, limiting the impact of internal changes on other blocks.
Question 11: In iSAQB terminology, what is the primary difference between an architecture decision and a design decision?
- Architecture decisions are made by managers; design decisions are made by developers
- Architecture decisions are hard to change and have wide impact; design decisions are more localized and reversible (Correct answer)
- There is no meaningful distinction between the two terms
- Architecture decisions only concern infrastructure; design decisions concern application logic
Correct answer: Architecture decisions are hard to change and have wide impact; design decisions are more localized and reversible
Architecture decisions are characterized by their broad impact and difficulty to reverse, while design decisions are more localized and easier to change.
Question 12: A startup requires rapid feature delivery, accepting more technical debt. How does this business constraint affect architectural decisions?
- It mandates microservices for maximum team independence
- It favors simpler, less modular designs that speed delivery over long-term maintainability (Correct answer)
- It requires formal architecture reviews before every commit
- It forces adoption of the most mature and proven technology stack
Correct answer: It favors simpler, less modular designs that speed delivery over long-term maintainability
Time-to-market pressure as a business constraint shifts the tradeoff toward simpler designs that reduce initial development time even at the cost of future modifiability.
Question 13: Which design principle states that a class should have only one reason to change?
- Single Responsibility Principle (Correct answer)
- Interface Segregation Principle
- Open/Closed Principle
- Liskov Substitution Principle
Correct answer: Single Responsibility Principle
The Single Responsibility Principle (SRP) states that a class should have only one reason to change, meaning it should have only one responsibility.
Question 14: What is the key characteristic that distinguishes Choreography-based sagas from Orchestration-based sagas?
- Choreography uses a central coordinator that directs each service step by step
- Choreography is only applicable to read-heavy workloads
- Orchestration requires services to publish events; choreography uses direct RPC calls
- In choreography, each service reacts to events autonomously without a central controller (Correct answer)
Correct answer: In choreography, each service reacts to events autonomously without a central controller
In choreography, services react to domain events published by other services without a central orchestrator, leading to decentralized and loosely coupled coordination.
Question 15: Which cross-cutting strategy reduces the blast radius of a misconfigured or compromised service in a microservices system?
- Principle of least privilege applied to service-to-service permissions (Correct answer)
- Shared database credentials for all services
- Disabling network segmentation for easier debugging
- Single API key for all inter-service calls
Correct answer: Principle of least privilege applied to service-to-service permissions
Least-privilege permissions limit what a compromised service can access, containing the damage to only the resources that service legitimately needs.
Question 16: A software architect is reviewing a legacy system and finds that business logic is spread across the UI, service, and database layers. Which architectural principle is being violated?
- Interface segregation
- Separation of concerns (Correct answer)
- Single responsibility at the class level
- Open/Closed principle
Correct answer: Separation of concerns
Separation of concerns requires that distinct responsibilities be assigned to distinct layers or components; mixing business logic across layers violates this principle.
Question 17: What is the difference between a vulnerability assessment and a penetration test?
- A vulnerability assessment uses automated tools while a penetration test is fully manual
- A vulnerability assessment produces no report while a penetration test does
- A vulnerability assessment identifies weaknesses without exploiting them; a penetration test actively exploits findings to demonstrate impact (Correct answer)
- A penetration test is always performed from outside the network
Correct answer: A vulnerability assessment identifies weaknesses without exploiting them; a penetration test actively exploits findings to demonstrate impact
Vulnerability assessments enumerate potential weaknesses, while penetration tests go further by actively exploiting vulnerabilities to prove real-world impact and chain attack paths.
Question 18: A quality tree (or utility tree) in ATAM is used to:
- Map user personas to functional requirements
- Organize and prioritize quality attribute scenarios from general utility down to concrete, measurable scenarios (Correct answer)
- Document the dependency graph between microservices
- Model the system's class hierarchy for object-oriented design
Correct answer: Organize and prioritize quality attribute scenarios from general utility down to concrete, measurable scenarios
A quality/utility tree decomposes system utility into quality attributes, then into refined attribute concerns, and finally into specific concrete scenarios with business and technical priority ratings.
Question 19: Which operating systems are commonly associated with the "IIS 8.5 Defaults" in the context of web server software?
- Windows Server 2012 R2, Windows 8.1 (Correct answer)
- Mysql
- Windows server 2016, windows 10 anniversary update
- Windows 7, 2008 r2
Correct answer: Windows Server 2012 R2, Windows 8.1
IIS 8.5 was introduced with Windows Server 2012 R2 and Windows 8.1. This version brought enhancements such as enhanced logging, dynamic IP address restrictions, and idle worker process page-out, improving performance and security for web hosting environments. It was a significant update from IIS 8.0, which shipped with Windows Server 2012 and Windows 8.
Question 20: What is the primary purpose of the Context View in software architecture documentation?
- To describe the sequence of interactions between components for a specific use case.
- To detail the internal modular structure and dependencies of the code.
- To show the system's boundaries and its relationships with external users, systems, and interfaces. (Correct answer)
- To map the software components to the underlying hardware infrastructure.
Correct answer: To show the system's boundaries and its relationships with external users, systems, and interfaces.
The Context View's main goal is to delimit the system from its environment. It identifies all external entities (users, other systems, APIs) that interact with the system, defining the system's scope and external interfaces without going into internal detail.
Question 21: What is 'decision paralysis' in the context of software architecture?
- A system outage caused by incorrect configuration decisions
- The inability to commit to an architectural decision due to over-analysis or fear of making the wrong choice (Correct answer)
- A formal review step before each deployment
- The process of delegating all decisions to the development team
Correct answer: The inability to commit to an architectural decision due to over-analysis or fear of making the wrong choice
Decision paralysis occurs when architects over-analyze options without converging on a choice, often delaying projects and increasing costs.
Question 22: Which quality attribute is MOST concerned with how easily a system can be moved from one environment to another?
- Maintainability
- Compatibility
- Portability (Correct answer)
- Interoperability
Correct answer: Portability
Portability (ISO 25010) addresses the ease of transferring a system to different hardware, software, or operational environments.
Question 23: Which of the following is a primary output of a successfully conducted Architecture Tradeoff Analysis Method (ATAM) evaluation?
- A documented set of identified architectural risks, sensitivity points, and tradeoff decisions. (Correct answer)
- A final project plan with guaranteed deadlines.
- A fully functional prototype of the system.
- A detailed list of required third-party software licenses.
Correct answer: A documented set of identified architectural risks, sensitivity points, and tradeoff decisions.
The main outputs of an ATAM evaluation are insights into the architecture's ability to meet its quality goals. This is documented through a set of identified risks (architectural decisions that could lead to problems), non-risks (decisions that are sound), sensitivity points (decisions that a quality attribute is highly dependent on), and tradeoffs (decisions that improve one attribute at the expense of another). [5, 6, 12] The goal is risk discovery, not creating prototypes or project plans. [5]
Question 24: Which technique is MOST appropriate for decoupling two building blocks that must communicate asynchronously?
- Message queues or event buses between the blocks (Correct answer)
- Shared global variables
- Remote procedure calls with synchronous return values
- Direct method calls via shared interfaces
Correct answer: Message queues or event buses between the blocks
Asynchronous message queues or event buses decouple sender and receiver in both time and knowledge, enabling independent evolution.
Question 25: When it comes to language vulnerabilities, which programming language is commonly associated with the vulnerability known as "Incorrect Element Removal"?
- Incorrect Element Removal (Correct answer)
- Mail Rcpt Data
- Log Injection Deadlock Language-based Attacks
- Root | Mysql
Correct answer: Incorrect Element Removal
The question asks which programming language is associated with 'Incorrect Element Removal', but the correct answer provided is 'Incorrect Element Removal' itself. This refers to a type of vulnerability where a program fails to properly remove or sanitize an element, potentially leading to security issues like information disclosure or bypasses. While not tied to a single specific language, it's a general class of vulnerability that can manifest in various programming contexts.
Question 26: In the context of CPSA, what is a 'quality scenario'?
- A performance benchmark run against a deployed system
- A user story describing business value from the end-user perspective
- A test case that validates functional behavior of a component
- A concrete, measurable description of how a quality attribute must be exhibited under specific conditions (Correct answer)
Correct answer: A concrete, measurable description of how a quality attribute must be exhibited under specific conditions
A quality scenario specifies stimulus, source, environment, artifact, response, and response measure to make quality requirements concrete and testable.
Question 27: In the context of architecture documentation, what is meant by 'appropriate level of detail'?
- Matching the number of pages to the project budget
- Using only high-level diagrams without any specifics
- Including enough detail to support the decisions and understanding needs of the intended audience, no more (Correct answer)
- Always documenting every method signature and variable
Correct answer: Including enough detail to support the decisions and understanding needs of the intended audience, no more
Appropriate detail means providing what stakeholders need to understand and act on the architecture without overwhelming them with unnecessary information.
Question 28: Which statement about quality attribute trade-offs is TRUE?
- High security measures can negatively impact performance and usability (Correct answer)
- Portability and testability always improve together
- Security and performance never conflict
- Increasing reliability always improves maintainability
Correct answer: High security measures can negatively impact performance and usability
Security controls such as encryption and authentication add overhead, which can increase latency and reduce system usability.
Question 29: In a quality scenario for 'modifiability', a realistic stimulus would be:
- A developer needs to add a new payment method to the checkout module (Correct answer)
- A hacker attempts a SQL injection attack
- A user submits a form at peak load
- A server loses power unexpectedly
Correct answer: A developer needs to add a new payment method to the checkout module
Modifiability scenarios are triggered by change requests, typically from developers, to alter system functionality.
Question 30: Which stakeholder group is MOST directly concerned with the operational quality attributes of a software system?
- Operations and infrastructure teams (Correct answer)
- Legal and compliance officers
- Business analysts
- End users
Correct answer: Operations and infrastructure teams
Operations and infrastructure teams are primarily concerned with operational quality attributes like availability, deployability, monitorability, and performance under load.
Question 31: Which of the following is a CORRECT way to express that Building Block A depends on Building Block B?
- A and B share the same internal data model
- A provides an interface that B implements
- B's required interface matches A's provided interface
- A's required interface matches B's provided interface (Correct answer)
Correct answer: A's required interface matches B's provided interface
A dependency from A to B means A requires a service that B provides — A's required interface is fulfilled by B's provided interface.
Question 32: Which trade-off is a direct consequence of applying the microservices architectural style compared to a monolith?
- Lower latency for all inter-component calls due to network proximity
- Increased operational complexity in exchange for independent deployability and scalability (Correct answer)
- Stronger data consistency guarantees across all services
- Simpler deployment pipeline but higher runtime coupling
Correct answer: Increased operational complexity in exchange for independent deployability and scalability
Microservices improve independent scalability and deployment but introduce distributed systems challenges such as network latency, eventual consistency, and complex operations.
Question 33: Which principle is MOST directly supported by using dependency injection?
- Liskov Substitution Principle
- Single Responsibility Principle
- Interface Segregation Principle
- Dependency Inversion Principle (Correct answer)
Correct answer: Dependency Inversion Principle
Dependency injection is a common technique for implementing the Dependency Inversion Principle, allowing high-level modules to depend on abstractions rather than concrete low-level classes.
Question 34: In the DES algorithm, how many cycles of 48-bit subkeys are used?
- Carrier Sense Multiple Access with Collision Avoidance
- Protected Extensible Authentication Protocol
- 56 bit key encryption (16 cycles of 48 bit subkeys) (Correct answer)
- 168 bit key encryption (48 cycles)
Correct answer: 56 bit key encryption (16 cycles of 48 bit subkeys)
The Data Encryption Standard (DES) algorithm uses a 56-bit key for encryption, although it takes a 64-bit input (8 bits are parity bits). During the encryption process, DES performs 16 rounds (cycles), and in each round, a unique 48-bit subkey is derived from the original 56-bit key and used to encrypt the data.
Question 35: During the initial design phase of a new financial services application, the legal department informs the architect that the system must comply with the Payment Card Industry Data Security Standard (PCI DSS). This is an example of what?
- An organizational or regulatory constraint (Correct answer)
- A technical goal
- A self-imposed constraint
- A functional requirement
Correct answer: An organizational or regulatory constraint
Compliance with legal or industry standards like PCI DSS is a type of organizational or regulatory constraint. It is imposed externally on the project and dictates specific security measures and design considerations that are non-negotiable for the architecture.
Question 36: An architect is told 'the system must use the company's existing Oracle database.' How should this be treated in architecture documentation?
- As a fixed technical constraint that bounds all data-related design decisions (Correct answer)
- As a functional requirement that defines what the system must do
- As a non-functional requirement with a measurable threshold
- As a recommendation that can be overridden with sufficient justification
Correct answer: As a fixed technical constraint that bounds all data-related design decisions
Mandated technology choices from the organization are fixed technical constraints that must be accepted and documented as non-negotiable boundaries.
Question 37: Which principle guides you to 'program to an interface, not an implementation'?
- Single Responsibility Principle
- Composition over Inheritance
- Dependency Inversion Principle (Correct answer)
- Law of Demeter
Correct answer: Dependency Inversion Principle
The Dependency Inversion Principle advocates programming to abstractions (interfaces) rather than concrete implementations to reduce high-level module dependency on low-level details.
Question 38: In the Strangler Fig pattern, what happens to the legacy system over time?
- New functionality wraps and gradually replaces the old system until the legacy is removed (Correct answer)
- It is immediately replaced in a big-bang migration
- It is kept running in parallel indefinitely
- It is refactored in place without deploying new services
Correct answer: New functionality wraps and gradually replaces the old system until the legacy is removed
Like a strangler fig vine, new services incrementally take over functionality from the legacy system until the old system can be decommissioned.
Question 39: An architect is reviewing a system design and finds a single building block that manages user authentication, generates PDF reports, and sends email notifications. Which design principle is most clearly being violated?
- Single Responsibility Principle (SRP) (Correct answer)
- Interface Segregation Principle (ISP)
- Dependency Inversion Principle (DIP)
- Don't Repeat Yourself (DRY)
Correct answer: Single Responsibility Principle (SRP)
The Single Responsibility Principle (SRP) states that a module or building block should have only one reason to change, meaning it should have only one primary responsibility. This block has three distinct responsibilities (authentication, reporting, notifications), thus violating SRP.
Question 40: Which of the following best describes a software architect's responsibility regarding cross-cutting concerns?
- Implementing cross-cutting concerns personally in every module
- Delegating all cross-cutting concerns to senior developers
- Identifying, documenting, and providing solutions for concerns that affect multiple components (Correct answer)
- Ignoring cross-cutting concerns until integration testing
Correct answer: Identifying, documenting, and providing solutions for concerns that affect multiple components
Software architects are responsible for identifying cross-cutting concerns such as logging, security, and error handling, and providing consistent architectural solutions for them.
Question 41: When using the arc42 documentation template, in which section would you primarily document the system's scope by identifying neighboring systems, users, and external interfaces?
- Section 5: Building Block View
- Section 3: Context and Scope (Correct answer)
- Section 8: Crosscutting Concepts
- Section 9: Architectural Decisions
Correct answer: Section 3: Context and Scope
The arc42 template explicitly dedicates Section 3, 'Context and Scope,' to defining the system's boundary. This section is used to describe all communication partners, such as users and external systems, and the interfaces through which they interact.
Question 42: When an architecture decision record (ADR) lists 'Consequences', what should that section contain?
- Both positive and negative outcomes resulting from the decision (Correct answer)
- The implementation timeline for the decision
- Only the risks that were rejected
- The names of stakeholders who approved the decision
Correct answer: Both positive and negative outcomes resulting from the decision
The Consequences section of an ADR documents all outcomes—positive, negative, and neutral—from adopting the decision.
Question 43: Which cross-cutting concern category includes audit logging, performance metrics collection, and health check endpoints?
- Security
- Reliability
- Observability (Correct answer)
- Scalability
Correct answer: Observability
Audit logs, metrics, and health checks all belong to observability — the cross-cutting concern of making a system's internal state and history visible to operators.
Question 44: What is the role of 'assumptions' in documenting architectural decisions?
- They list confirmed system requirements from the product backlog
- They describe the software licenses used in the project
- They identify conditions that are believed to be true but have not been verified, which could invalidate the decision if wrong (Correct answer)
- They specify the deployment hardware specifications
Correct answer: They identify conditions that are believed to be true but have not been verified, which could invalidate the decision if wrong
Documenting assumptions makes decision dependencies explicit, so if an assumption is later invalidated, the affected decision can be revisited.
Question 45: What problem does the 'Saga' pattern solve in distributed system integration?
- Synchronizing clocks between distributed services
- Routing traffic between microservices based on load
- Managing long-running distributed transactions across multiple services without using a two-phase commit (Correct answer)
- Optimizing database queries across multiple microservices
Correct answer: Managing long-running distributed transactions across multiple services without using a two-phase commit
The Saga pattern coordinates multi-step transactions across services using a sequence of local transactions with compensating actions to handle failures.
Question 46: How does the Conway's Law principle relate to architectural constraints?
- Conway's Law establishes security boundaries between components
- Conway's Law defines the maximum number of microservices allowed
- Organizational team structure creates an implicit constraint that shapes system architecture (Correct answer)
- Conway's Law specifies database normalization requirements
Correct answer: Organizational team structure creates an implicit constraint that shapes system architecture
Conway's Law states that systems mirror the communication structure of the organizations that design them, making org structure an implicit architectural constraint.
iSAQB Certified Professional for Software Architecture (CPSA) Exam
The iSAQB CPSA exam certifies software architects in architectural fundamentals, designing building blocks, cross-cutting concerns, quality attributes, architectural patterns, integration, and architecture evaluation.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds