CISSP-ISSAP: Information Systems Security Architecture Professional — Questions and Answers
Question 1: To enhance its security operations, an organization wants to operationalize threat intelligence. The architect's design calls for a central system that can ingest threat data from multiple feeds (e.g., open-source, commercial, ISACs), deduplicate and normalize the data, enrich it with context, and then share actionable indicators with other security tools like the SIEM, firewalls, and EDR. Which type of platform BEST describes this central system?
- A vulnerability management platform.
- A Threat Intelligence Platform (TIP). (Correct answer)
- A Security Orchestration, Automation, and Response (SOAR) platform.
- A next-generation Security Information and Event Management (SIEM).
Correct answer: A Threat Intelligence Platform (TIP).
This describes the core function of a Threat Intelligence Platform (TIP). A TIP is a technology solution designed to aggregate, process, and analyze threat data from multiple sources. [22, 18] It manages the intelligence lifecycle by normalizing data, enriching it with context, and integrating with other security controls to operationalize the intelligence for detection and prevention. [7, 25]
Question 2: Which design approach BEST improves network resilience by eliminating single points of failure at the network layer?
- Deploying all servers in a single subnet for easier management
- Implementing redundant links with dynamic routing protocols such as OSPF or BGP (Correct answer)
- Consolidating all switching to one core switch with a hot spare
- Using a single high-capacity firewall with RAID storage
Correct answer: Implementing redundant links with dynamic routing protocols such as OSPF or BGP
Redundant links combined with dynamic routing protocols allow traffic to automatically reroute around failures, eliminating single points of failure and improving network resilience.
Question 3: What is a key component of risk analysis in cybersecurity?
- Identifying stakeholders
- Selecting cloud service providers
- Determining threat sources and vulnerabilities (Correct answer)
- Writing security policies
Correct answer: Determining threat sources and vulnerabilities
A key component of risk analysis involves identifying potential threat sources (e.g., hackers, natural disasters) and the vulnerabilities within systems or processes that these threats could exploit. Understanding these elements is crucial for assessing the likelihood and potential impact of a security incident.
Question 4: A security architect is designing a new network architecture for a highly distributed organization with a large remote workforce and extensive use of cloud applications. The goal is to move away from a traditional hub-and-spoke model that backhauls traffic to a central data center. Which of the following frameworks converges network and security functions into a single, cloud-delivered service, providing optimized and secure access for users regardless of their location?
- Microsegmentation
- Secure Access Service Edge (SASE) (Correct answer)
- Defense-in-Depth
- Intrusion Prevention System (IPS)
Correct answer: Secure Access Service Edge (SASE)
Secure Access Service Edge (SASE) is an architectural framework that converges networking capabilities (like SD-WAN) with cloud-native security functions (like CASB, FWaaS, and ZTNA) into a single, cloud-delivered service. This model is designed to provide secure and optimized access to applications and data for a distributed workforce, eliminating the need to backhaul traffic to a central data center for security inspection.
Question 5: As part of the NIST Risk Management Framework (RMF), a security architect is responsible for defining the initial set of security controls for a new information system. This selection is based on the system's security categorization. Which step of the RMF is being performed?
- Assess Controls
- Authorize System
- Categorize System
- Select Controls (Correct answer)
Correct answer: Select Controls
The 'Select Controls' step of the NIST RMF involves choosing an initial baseline of security controls for an information system based on its security categorization (determined in the 'Categorize System' step). The architect then tailors this baseline to align with the organization's specific risk tolerance and operational environment.
Question 6: Which of the following enterprise architecture frameworks is structured as an ontology, providing a schema for organizing architectural artifacts based on six interrogatives (What, How, Where, Who, When, Why) and six different perspectives (e.g., Planner, Owner, Designer)?
- Zachman Framework (Correct answer)
- SABSA
- TOGAF
- ITIL
Correct answer: Zachman Framework
The Zachman Framework is an enterprise ontology and schema for organizing and classifying architectural artifacts. It is structured as a two-dimensional matrix with columns representing interrogatives (What, How, Where, etc.) and rows representing different stakeholder perspectives (Planner, Owner, etc.). It is not a methodology but a way to ensure all aspects of an enterprise are considered from various points of view.
Question 7: A Security Operations Center (SOC) is consistently overwhelmed by the high volume of phishing alerts. Analysts perform the same manual steps for each alert: analyze the email headers, detonate suspicious URLs in a sandbox, check indicators against threat intelligence feeds, and, if malicious, block the indicators and isolate the host. A security architect wants to implement a solution to automate this entire workflow. Which technology is specifically designed for this purpose?
- Threat Intelligence Platform (TIP)
- User and Entity Behavior Analytics (UEBA)
- Security Orchestration, Automation, and Response (SOAR) (Correct answer)
- Endpoint Detection and Response (EDR)
Correct answer: Security Orchestration, Automation, and Response (SOAR)
A Security Orchestration, Automation, and Response (SOAR) platform is designed to address this exact use case. [11] Orchestration connects disparate security tools (sandbox, TIP, EDR, firewall), while automation executes predefined workflows, known as playbooks, to perform response actions without manual intervention. [32, 34] This allows the SOC to automate the repetitive tasks associated with phishing response, freeing up analysts to focus on more complex threats. [11]
Question 8: In a traditional three-tier network architecture, what is the primary security purpose of a DMZ (Demilitarized Zone)?
- To terminate VPN connections from remote users
- To host internal databases securely
- To aggregate logs from all internal systems
- To isolate publicly accessible services from the internal network (Correct answer)
Correct answer: To isolate publicly accessible services from the internal network
The DMZ hosts publicly accessible services (e.g., web servers) while isolating them from the internal network, so external threats cannot directly reach internal resources.
Question 9: A security architect is establishing a proactive threat hunting program. The primary goal is to search for previously unknown or undetected threats that have bypassed existing security controls. Which of the following is the MOST critical architectural prerequisite for enabling effective, hypothesis-driven threat hunting?
- A centralized, long-term repository of searchable endpoint, network, and log data. (Correct answer)
- A real-time dashboard showing alerts from perimeter security devices.
- A complete set of incident response playbooks for all known threat types.
- An automated patching and vulnerability management system.
Correct answer: A centralized, long-term repository of searchable endpoint, network, and log data.
Effective threat hunting is fundamentally dependent on having access to rich, historical data. [21] A centralized and searchable repository (often a data lake or advanced SIEM) containing endpoint process logs, network flow data, DNS queries, and other telemetry is essential. [8] This allows hunters to form a hypothesis (e.g., "an attacker is using DNS for command and control") and then query the historical data to find anomalies and patterns that would not trigger a traditional alert. [21, 23]
Question 10: An enterprise wants to enforce consistent security policies for network access by verifying endpoint posture before granting connectivity. Which technology BEST supports this requirement?
- Dynamic Host Configuration Protocol (DHCP)
- VPN split tunneling
- Network Address Translation (NAT)
- Network Access Control (NAC) (Correct answer)
Correct answer: Network Access Control (NAC)
Network Access Control (NAC) evaluates the security posture of endpoints (patch level, antivirus status, etc.) before permitting them to connect to network segments.
Question 11: A security architect is leveraging Software-Defined Networking (SDN) for security. Which capability of SDN BEST enhances the security posture?
- Reduces the number of VLANs required in the network
- Eliminates the need for encryption on internal links
- Enables centralized, programmable policy enforcement across the network (Correct answer)
- Replaces firewalls with hardware load balancers
Correct answer: Enables centralized, programmable policy enforcement across the network
SDN's centralized control plane allows security policies to be programmatically defined and consistently enforced across all network devices from a single controller.
Question 12: A security architect is designing the identity lifecycle management process for a large enterprise. The architect must ensure that access rights are correctly assigned when an employee is hired, adjusted when they change roles, and revoked promptly when they leave. Which of the following frameworks is specifically designed to address these stages of the identity lifecycle?
- Joiner-Mover-Leaver (JML) (Correct answer)
- Zachman Framework
- TOGAF (The Open Group Architecture Framework)
- SABSA (Sherwood Applied Business Security Architecture)
Correct answer: Joiner-Mover-Leaver (JML)
The Joiner-Mover-Leaver (JML) framework is a core process within identity and access management that specifically outlines the procedures for onboarding (Joiner), role changes (Mover), and offboarding (Leaver). It ensures that user access privileges are managed dynamically and appropriately throughout their tenure with an organization, enforcing principles like least privilege. The other options are enterprise architecture frameworks, not specific IAM process models.
Question 13: Which of the following is a primary role of a security architect in the context of Governance, Risk, and Compliance (GRC)?
- Designing and developing security solutions that align with business strategy, policies, and regulatory requirements. (Correct answer)
- Performing daily security operations and incident response.
- Conducting forensic analysis of compromised systems after a security breach.
- Configuring and managing firewall rules and intrusion detection systems.
Correct answer: Designing and developing security solutions that align with business strategy, policies, and regulatory requirements.
A security architect's primary role within GRC is to design security solutions and architectures that are aligned with the organization's vision, mission, strategy, policies, and external factors like laws and regulations. They translate GRC objectives into technical and architectural requirements, ensuring that the security posture supports business goals while managing risk and maintaining compliance.
Question 14: A financial services firm is architecting a hybrid cloud solution that requires a stable, high-bandwidth, and low-latency connection for replicating large volumes of sensitive transaction data between its on-premises data center and its cloud environment. Public internet performance variability is not acceptable. Which connectivity method BEST meets these requirements?
- A multi-region VPC peering connection
- An SSL VPN established from each on-premises server to the cloud
- A dedicated private network connection (e.g., AWS Direct Connect, Azure ExpressRoute) (Correct answer)
- A site-to-site IPsec VPN over the public internet
Correct answer: A dedicated private network connection (e.g., AWS Direct Connect, Azure ExpressRoute)
A dedicated private network connection, such as AWS Direct Connect or Azure ExpressRoute, provides a private, physical link between the on-premises environment and the cloud provider's network. This approach bypasses the public internet entirely, resulting in consistent low latency, high bandwidth, and enhanced security, making it ideal for performance-sensitive and critical workloads like large-scale data replication.
Question 15: Which of the following is the PRIMARY reason for implementing a key rotation policy as part of a cryptographic key management lifecycle?
- To limit the amount of data exposed if a key is compromised. (Correct answer)
- To improve cryptographic performance.
- To simplify the key backup and recovery process.
- To comply with data retention policies.
Correct answer: To limit the amount of data exposed if a key is compromised.
The primary security benefit of key rotation is to limit the 'blast radius' if a key is compromised. By regularly changing keys, the amount of data encrypted with any single key is reduced. Therefore, if an attacker compromises one key, they can only decrypt the data protected by that specific key during its limited crypto-period, not the entire history of the data.
Question 16: An organization is transitioning to IPv6. Which security consideration is MOST important for a security architect to address during the transition?
- IPv6 eliminates the need for network address translation
- Dual-stack environments may expose IPv6 interfaces that bypass existing IPv4 security controls (Correct answer)
- IPv6 uses smaller address spaces that simplify firewall rule management
- IPv6 does not support IPsec and requires alternative encryption
Correct answer: Dual-stack environments may expose IPv6 interfaces that bypass existing IPv4 security controls
In dual-stack environments, systems expose both IPv4 and IPv6 interfaces; existing security controls configured only for IPv4 may not inspect IPv6 traffic, creating blind spots.
Question 17: Which of the following is a significant architectural challenge that can arise from the overuse or improper design of a Role-Based Access Control (RBAC) model in a large, complex organization?
- Role explosion (Correct answer)
- Protocol decay
- Policy stagnation
- Attribute explosion
Correct answer: Role explosion
Role explosion, or role proliferation, is a common problem in large-scale RBAC implementations. It occurs when an excessive number of granular roles are created to address specific access needs, making the model difficult to manage, audit, and scale. This complexity can undermine the initial simplicity that RBAC is intended to provide. Attribute explosion is a potential challenge for ABAC, not RBAC.
Question 18: As a security architect for a financial services company, you are evaluating solutions to streamline user access across dozens of cloud-based (SaaS) and on-premises applications. The primary goals are to improve user experience with single sign-on (SSO), centralize identity management, and reduce the administrative burden of managing credentials in multiple systems. Which of the following architectural approaches BEST meets these requirements?
- Adopting an Identity as a Service (IDaaS) solution. (Correct answer)
- Establishing a manual, ticket-based provisioning and de-provisioning process.
- Implementing a standalone Security Information and Event Management (SIEM) system.
- Deploying a host-based intrusion detection system (HIDS) on all application servers.
Correct answer: Adopting an Identity as a Service (IDaaS) solution.
Identity as a Service (IDaaS) is a cloud-based subscription model that provides comprehensive identity and access management capabilities, including Single Sign-On (SSO), multi-factor authentication, and centralized user management. This directly addresses the company's need to streamline access across hybrid environments, improve user experience, and reduce administrative overhead. A SIEM is for monitoring, a HIDS is for host-level threat detection, and a manual process would increase, not decrease, administrative burden.
Question 19: A security architect is designing an infrastructure with the principle of "forensic readiness" in mind. The primary objective is to ensure that in the event of a security incident, reliable digital evidence can be collected efficiently and its integrity maintained for an investigation. Which architectural design choice is MOST foundational to achieving this objective?
- Deploying a deception technology grid to lure attackers.
- Mandating annual incident response tabletop exercises.
- Enabling comprehensive, immutable, and centrally-managed logging for all critical systems and network devices. (Correct answer)
- Implementing the fastest available storage for all systems.
Correct answer: Enabling comprehensive, immutable, and centrally-managed logging for all critical systems and network devices.
Forensic readiness is a proactive approach to prepare for investigations before an incident occurs. [24] The most critical foundation is having a reliable record of events. Enabling comprehensive logging across all relevant assets provides the raw data needed for analysis. [31] Ensuring these logs are immutable (write-once, read-many) and centrally managed prevents tampering and guarantees that a verifiable trail of evidence is available for investigators, forming the basis of any digital forensic investigation. [24, 31]
Question 20: Which firewall deployment model inspects traffic based on the state of network connections and is considered more secure than simple packet filtering?
- Application-layer proxy
- Circuit-level gateway
- Stateful inspection firewall (Correct answer)
- Stateless packet filtering
Correct answer: Stateful inspection firewall
A stateful inspection firewall tracks the state of active connections and uses this context to enforce policy, blocking packets that don't belong to a known legitimate session.
Question 21: A security architect must ensure that sensitive network traffic between data centers is protected in transit. Which solution provides both confidentiality and integrity for this traffic?
- IPsec tunnel mode between data center gateways (Correct answer)
- QoS tagging on the WAN links
- MPLS traffic engineering without encryption
- Using private WAN circuits without additional encryption
Correct answer: IPsec tunnel mode between data center gateways
IPsec tunnel mode encrypts the entire original IP packet and provides both confidentiality and integrity verification, protecting data in transit between data centers.
Question 22: An architect is designing a Security Information and Event Management (SIEM) architecture for a large enterprise. A primary requirement is to process high-volume log data from thousands of diverse sources, including firewalls, servers, and custom applications, each with a unique format. Which SIEM component is fundamentally responsible for parsing these varied log formats into a standardized, common schema before they are sent to the correlation engine?
- The correlation and analytics engine.
- The reporting and dashboarding module.
- The log storage and data lake.
- The data collection and normalization layer. (Correct answer)
Correct answer: The data collection and normalization layer.
The data collection and normalization layer is the core component responsible for this function. [5] Collectors or agents gather raw logs from various sources. [1, 3] The normalization process then parses the different log formats, extracts key fields, and transforms them into a common, standardized format (schema). This step is critical because the correlation engine requires a consistent data structure to apply rules and detect patterns across disparate data sources effectively. [3]
Question 23: What is the primary purpose of a risk assessment?
- To provide cost estimates for cybersecurity tools
- To identify and evaluate risks to inform decision-making (Correct answer)
- To eliminate all risks
- To ensure compliance with industry regulations
Correct answer: To identify and evaluate risks to inform decision-making
The primary purpose of a risk assessment is to systematically identify potential threats and vulnerabilities, analyze the likelihood and impact of these risks, and then use this information to make informed decisions about risk treatment and mitigation strategies. It helps organizations understand their security posture.
Question 24: What is the primary purpose of identity federation?
- To enforce stronger password policies
- To centralize all user accounts in one database
- To enable seamless access across multiple systems or organizations (Correct answer)
- To encrypt all user credentials
Correct answer: To enable seamless access across multiple systems or organizations
Identity federation allows users to use a single set of login credentials to access resources across different, independent security domains or applications without needing to re-authenticate. This enhances user experience and simplifies identity management, especially in cloud environments or inter-organizational collaborations.
Question 25: A security architect is designing a system to protect sensitive data that will be stored for over 20 years. The architect is concerned about the future threat of quantum computing rendering current asymmetric encryption algorithms obsolete. Which of the following is the MOST important architectural principle to incorporate into the design to mitigate this long-term risk?
- Cryptographic agility (Correct answer)
- Homomorphic encryption
- Perfect forward secrecy
- Data fragmentation
Correct answer: Cryptographic agility
Cryptographic agility is the design principle that allows an information system to easily and quickly replace or update its cryptographic algorithms, keys, and protocols without major disruptions. This is crucial for long-term data protection, as it prepares the system for the eventual transition to post-quantum cryptography (PQC) algorithms, which are resistant to attacks from quantum computers. While other options are valid security concepts, they do not directly address the need to adapt to future, unforeseen weaknesses in specific cryptographic algorithms.
Question 26: What is the primary function of a hash algorithm in cryptography?
- To facilitate secure communication
- To create a unique fixed-length representation of data (Correct answer)
- To generate keys for encryption
- To encrypt and decrypt data
Correct answer: To create a unique fixed-length representation of data
A hash algorithm takes an input (or 'message') and returns a fixed-size alphanumeric string, known as a hash value or message digest. This unique representation is used to verify data integrity, as even a small change in the input data will produce a completely different hash value.
Question 27: A security architect at a multinational corporation is tasked with designing a security architecture that can adapt to a complex and constantly changing regulatory landscape. The architecture must provide a consistent set of reusable security services, such as identity management and network segmentation, across all business units. What is the main benefit of this architectural approach?
- It reduces the initial cost of security implementation to near zero.
- It eliminates the need for all future security testing.
- It provides standardization that simplifies demonstrating compliance across multiple regulations. (Correct answer)
- It completely outsources all security risks to third-party vendors.
Correct answer: It provides standardization that simplifies demonstrating compliance across multiple regulations.
A well-designed security architecture that uses consistent, standardized building blocks and common security services simplifies the process of meeting diverse regulatory obligations. This consistency makes it easier to audit, manage, and demonstrate compliance across the enterprise, even when regulations change or overlap.
Question 28: Which of the following represents the MOST significant security challenge unique to a serverless (FaaS) architecture compared to a traditional Infrastructure as a Service (IaaS) model where the organization manages the full OS?
- The requirement to configure network-level firewalls and security groups.
- The responsibility for physical security of the data center hardware.
- The need for vulnerability scanning of operating systems and kernel patching.
- An expanded and more complex attack surface due to event-triggers and function-to-function interactions. (Correct answer)
Correct answer: An expanded and more complex attack surface due to event-triggers and function-to-function interactions.
In a serverless architecture, the attack surface shifts from the underlying OS (which is managed by the cloud provider) to the functions themselves and their triggers. Each function can be triggered by numerous event sources (HTTP APIs, storage events, message queues), creating many more entry points for an attacker. Securing the interactions and permissions between dozens or hundreds of ephemeral functions introduces a complexity not present in managing a few monolithic VMs.
Question 29: During a threat modeling session for a new online payment application, the security team is categorizing potential threats. An attacker attempting to modify the transaction amount after it has been submitted but before it is processed would fall under which category of the STRIDE model?
- Repudiation
- Spoofing
- Information Disclosure
- Tampering (Correct answer)
Correct answer: Tampering
The STRIDE model categorizes threats to help analyze a system for security vulnerabilities. Tampering refers to the unauthorized modification of data. In this scenario, altering the transaction amount is a direct manipulation of data, which is a classic example of a tampering threat. Spoofing relates to impersonation, Repudiation to denying an action, and Information Disclosure to exposing data to unauthorized parties.
Question 30: What is a service provider (SP) in identity federation?
- A network that connects identity providers
- A system that relies on identity information from an IdP to grant access (Correct answer)
- The organization that owns the user credentials
- A protocol used for password encryption
Correct answer: A system that relies on identity information from an IdP to grant access
A Service Provider (SP) is an application or service that relies on an Identity Provider (IdP) to authenticate users. Instead of managing its own user credentials, the SP trusts the IdP to verify the user's identity. Upon successful authentication by the IdP, the SP receives identity information and grants the user access to its resources.
Question 31: What is the first step in the risk assessment process?
- Identifying assets and their value (Correct answer)
- Implementing risk controls
- Performing a gap analysis
- Monitoring and reviewing risks
Correct answer: Identifying assets and their value
The initial step in any risk assessment process is to identify and categorize the assets that need protection, such as data, systems, and infrastructure. Understanding the value and criticality of these assets helps prioritize security efforts and determine the potential impact of a security incident.
Question 32: An organization is building a partnership with several external companies, allowing their employees to access a shared collaboration portal. To avoid creating and managing separate user accounts for each partner employee, the security architect needs to design a solution where users can authenticate with their own corporate credentials. Which of the following technologies is fundamental to enabling this cross-domain trust and authentication?
- Lightweight Directory Access Protocol (LDAP)
- Federated Identity Management (FIM) (Correct answer)
- RADIUS
- Kerberos
Correct answer: Federated Identity Management (FIM)
Federated Identity Management (FIM) is the architectural pattern and set of standards (like SAML and OpenID Connect) that allows identities from one trust domain (the partner company) to be accepted by a service provider in another trust domain (the collaboration portal). This enables users to use their existing corporate credentials, establishing a trust relationship between the identity provider and the service provider. Kerberos and LDAP are typically used within a single organizational domain, and RADIUS is often used for network access control.
Question 33: A global e-commerce company is developing a comprehensive risk management strategy. They want to adopt a set of high-level principles to guide the integration of risk management into all organizational activities, ensuring it is dynamic, customized, and structured. Which international standard provides such principles for risk management?
- ISO/IEC 27005
- SABSA
- ISO 31000 (Correct answer)
- ISO 9001
Correct answer: ISO 31000
ISO 31000 is an international standard that provides principles, a framework, and a process for managing risk. It is not specific to any industry and focuses on integrating risk management throughout an organization's governance, strategy, and operations. Its core principles include integration, a structured approach, customization, and continual improvement.
Question 34: Which network security architecture model uses software-defined perimeters to make infrastructure invisible to unauthorized users before authentication occurs?
- VPN with split tunneling
- NAT-based access control
- Traditional firewall-based perimeter
- Software-Defined Perimeter (SDP) / Zero Trust Network Access (ZTNA) (Correct answer)
Correct answer: Software-Defined Perimeter (SDP) / Zero Trust Network Access (ZTNA)
SDP/ZTNA makes network resources invisible (dark) to unauthenticated users and only establishes encrypted connections to specific resources after identity and device posture are verified.
Question 35: Which of the following is the primary goal of security design principles?
- To lower operational costs
- To increase system usability
- To ensure system availability only
- To reduce vulnerabilities and mitigate risks (Correct answer)
Correct answer: To reduce vulnerabilities and mitigate risks
The primary goal of security design principles is to build systems that are inherently resilient against attacks. By incorporating these principles, architects aim to minimize potential weaknesses (vulnerabilities) and reduce the likelihood and impact of security incidents (risks).
Question 36: A company is deploying microservices using Docker containers. The security architect is concerned about vulnerabilities within the third-party and open-source libraries included in the container images. Which of the following is the MOST effective control to implement early in the CI/CD pipeline to mitigate this specific risk?
- Implementing strict Kubernetes Network Policies
- Enforcing mandatory access control (MAC) on host nodes
- Runtime container security monitoring
- Software Composition Analysis (SCA) (Correct answer)
Correct answer: Software Composition Analysis (SCA)
Software Composition Analysis (SCA) tools are specifically designed to scan an application's dependencies, including container images, to identify all third-party and open-source components and their known vulnerabilities (CVEs). Integrating an SCA scanner into the CI/CD pipeline allows for early detection of vulnerable libraries before the container image is even stored in a registry or deployed.
Question 37: A security architect is defining the security verification requirements for a new web application that will handle sensitive medical data (PHI). The application requires the highest level of security assurance. According to the OWASP Application Security Verification Standard (ASVS), which level should be specified?
- Level 4
- Level 3 (Correct answer)
- Level 1
- Level 2
Correct answer: Level 3
The OWASP ASVS defines three security verification levels. Level 3 is the highest and most stringent level, intended for the most critical applications, such as those that handle high-value transactions, sensitive medical data, or any application requiring the highest level of trust. Level 1 is for low-assurance needs, and Level 2 is the standard for applications handling sensitive data. There is no Level 4 in the ASVS standard.
Question 38: What is the primary goal of cryptography in information security?
- To enforce authentication policies
- To protect confidentiality, integrity, and authenticity of data (Correct answer)
- To ensure user accountability
- To prevent denial-of-service attacks
Correct answer: To protect confidentiality, integrity, and authenticity of data
Cryptography is fundamentally used to secure communication and data storage by protecting confidentiality, integrity, and authenticity of data. It achieves this by preventing unauthorized disclosure, modification, and ensuring the verifiable origin and genuineness of information.
Question 39: Which network security monitoring approach captures full packet data for retrospective analysis of security incidents?
- SNMP polling
- NetFlow analysis
- Full packet capture (PCAP) (Correct answer)
- Syslog aggregation
Correct answer: Full packet capture (PCAP)
Full packet capture (PCAP) records the complete contents of network packets, enabling security analysts to reconstruct sessions and perform detailed forensic analysis after an incident.
Question 40: A security architect wants to implement a testing methodology that can identify insecure coding practices, such as potential SQL injection or buffer overflow vulnerabilities, by analyzing the application's source code without executing it. Which testing methodology should be chosen?
- Static Application Security Testing (SAST) (Correct answer)
- Fuzz Testing
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
Correct answer: Static Application Security Testing (SAST)
Static Application Security Testing (SAST), also known as 'white-box' testing, analyzes an application's source code, byte code, or binary code for security vulnerabilities without executing the program. It is effective at finding issues like SQL injection, buffer overflows, and other insecure coding patterns early in the SDLC. DAST, or 'black-box' testing, analyzes a running application from the outside, while IAST combines elements of both. Fuzz testing involves providing invalid or random data to an application to see how it responds.
Question 41: A security architect is embedding compliance requirements into the technology infrastructure from the initial design phase. This proactive approach ensures that controls for data protection, access management, and privacy are built-in rather than added later, significantly reducing the cost and effort of retrofitting. This practice is best described as which of the following?
- Compliance as Code
- Risk Transference
- Defense in Depth
- Security by Design (Correct answer)
Correct answer: Security by Design
Security by Design, also referred to as Secure by Design, is the principle of integrating security considerations and controls into the system development lifecycle from the very beginning. This approach ensures that compliance and security are fundamental components of the architecture, rather than afterthoughts that require costly retrofitting.
Question 42: A security architect is designing a multi-level secure (MLS) database for a government agency. The primary requirement is to prevent an inference attack where a user with a low clearance could deduce the existence of high-level data by observing an error or a null result. Which database security mechanism is specifically designed to mitigate this type of attack?
- Homomorphic Encryption
- Data Masking
- Polyinstantiation (Correct answer)
- Database Activity Monitoring (DAM)
Correct answer: Polyinstantiation
Polyinstantiation is a database security technique used in multi-level secure systems to prevent inference attacks. It allows multiple records with the same primary key to exist in the database, but with different security classifications. A user with a low clearance level would see a different, less-sensitive version of the record instead of an error, preventing them from inferring that a higher-classification record exists.
Question 43: Which security design principle involves dividing a system into smaller parts to reduce overall risk?
- Fail-safe defaults
- Security through obscurity
- Economy of mechanism
- Separation of duties (Correct answer)
Correct answer: Separation of duties
Separation of duties is a security design principle that involves dividing critical tasks among multiple individuals or components to prevent any single person or entity from having complete control. This reduces the risk of fraud, error, or malicious activity by requiring collusion to compromise the system.
Question 44: A financial institution is undergoing a security architecture review. The architect notes that the current network is a large, flat design where application servers, user workstations, and development systems all reside on the same broadcast domain. Which security design practice would provide the MOST significant improvement in limiting the lateral movement of an attacker?
- Deploying a Web Application Firewall (WAF) for the public-facing website.
- Performing network segmentation using VLANs and firewalls. (Correct answer)
- Upgrading all network switches to the latest firmware.
- Implementing a new password complexity policy.
Correct answer: Performing network segmentation using VLANs and firewalls.
In a flat network, once an attacker compromises a single host, they can easily move laterally to attack other systems on the same network. Network segmentation divides the network into smaller, isolated zones (e.g., for production servers, user devices, development). By placing firewalls or access control lists (ACLs) between these segments, an organization can enforce strict access controls, containing a potential breach within a single segment and significantly hindering an attacker's ability to move laterally across the infrastructure.
Question 45: An architect is applying the defense-in-depth strategy to secure a critical application server. The design includes a perimeter firewall, network segmentation, host-based intrusion prevention system (HIPS), application-level access controls, and data encryption. What is the primary purpose of this layered approach?
- To eliminate the need for security monitoring and logging.
- To meet the minimum compliance requirements with a single security solution.
- To ensure that if one security control fails, others may still be effective in stopping an attack. (Correct answer)
- To focus all security resources on preventing initial network penetration.
Correct answer: To ensure that if one security control fails, others may still be effective in stopping an attack.
The core concept of defense-in-depth is that no single security control is infallible. By implementing multiple, overlapping layers of security, the architecture creates redundancy. If an attacker bypasses one layer (e.g., the perimeter firewall), other layers (like network segmentation or HIPS) are in place to detect or prevent further progress, thus enhancing the overall resilience of the system.
Question 46: A security architect is designing a Zero Trust network. Which of the following BEST describes the core tenet of Zero Trust?
- Never trust, always verify — regardless of network location (Correct answer)
- Perimeter firewalls are sufficient to enforce trust boundaries
- All internal traffic is trusted by default
- Trust is granted after a single successful authentication
Correct answer: Never trust, always verify — regardless of network location
Zero Trust operates on 'never trust, always verify,' requiring continuous authentication and authorization for every request regardless of where it originates.
Question 47: Which VPN architecture model routes all remote user traffic — including internet-bound traffic — through the corporate network for inspection?
- Full tunneling (Correct answer)
- SSL portal VPN
- Hub-and-spoke MPLS
- Split tunneling
Correct answer: Full tunneling
Full tunneling directs all remote user traffic through the corporate VPN gateway, allowing the enterprise to inspect and control all traffic including internet browsing.
Question 48: Micro-segmentation in a data center environment is MOST effective at controlling which type of traffic?
- Management traffic to network devices
- Traffic between branch offices over MPLS
- North-south traffic from the internet to servers
- East-west traffic between workloads within the data center (Correct answer)
Correct answer: East-west traffic between workloads within the data center
Micro-segmentation applies granular policies to east-west (lateral) traffic between workloads inside the data center, preventing lateral movement by attackers.
Question 49: An organization is preparing for a transition to post-quantum cryptography (PQC) in anticipation of future threats. The security architect has been tasked with creating a readiness plan. Which of the following is the MOST critical first step in this plan?
- Decommission all systems that do not support cryptographic agility.
- Immediately replace all RSA and ECC algorithms with PQC alternatives.
- Create an inventory of all systems and applications that use cryptography. (Correct answer)
- Procure quantum computing hardware for internal testing.
Correct answer: Create an inventory of all systems and applications that use cryptography.
Before any migration can occur, an organization must understand its current cryptographic landscape. Creating a comprehensive inventory of where cryptography is used, which algorithms and key lengths are implemented, and their business criticality is the essential first step. This inventory allows the organization to prioritize migration efforts, identify dependencies, and develop a strategic roadmap for a phased transition to PQC, addressing the most critical and sensitive assets first.
Question 50: Which protocol is commonly used for identity federation?
- FTP
- SMTP
- OAuth (Correct answer)
- DNS
Correct answer: OAuth
OAuth is an open standard for access delegation, commonly used for identity federation. It allows a user to grant a third-party application limited access to their resources on another service without sharing their credentials. This protocol facilitates secure and delegated authorization, making it a key component in modern identity federation architectures.
Question 51: What does the term identity provider (IdP) mean in a federated identity system?
- A user who manages credentials
- A firewall that filters user requests
- A service that authenticates users and provides identity information (Correct answer)
- A database where user activities are logged
Correct answer: A service that authenticates users and provides identity information
An Identity Provider (IdP) is a trusted entity in a federated identity system responsible for authenticating a user's identity. Once authenticated, the IdP issues an assertion or token containing the user's identity information to a service provider. This allows the user to access resources on the service provider without directly sharing their credentials with it.
Question 52: A security architect is designing a network for a manufacturing plant that uses Industrial Control Systems (ICS) and SCADA for process automation. A primary security goal is to prevent threats from the corporate IT network from impacting the operational technology (OT) network. Which design principle is MOST critical to implement?
- Enforcing multi-factor authentication for all corporate users.
- Strict network segmentation with a demilitarized zone (DMZ) between the IT and OT networks. (Correct answer)
- Implementing end-to-end encryption for all SCADA traffic.
- Deploying a host-based intrusion detection system on all PLCs.
Correct answer: Strict network segmentation with a demilitarized zone (DMZ) between the IT and OT networks.
Strict network segmentation is a foundational security control for protecting ICS/SCADA environments. Creating a DMZ between the IT and OT networks allows for controlled and monitored communication while preventing direct traffic, which significantly reduces the risk of malware or attacks spreading from the less-secure corporate network to the critical OT environment. While other controls are valuable, segmentation provides the most critical architectural defense against this specific threat vector.
Question 53: Which of the following is a core principle of a Zero Trust Architecture (ZTA) that fundamentally changes the traditional network security paradigm?
- Relying solely on network location for access control decisions.
- Assuming breach and verifying each access request as if it originates from an open network. (Correct answer)
- Trusting all traffic originating from within the corporate firewall.
- Establishing a single, hardened network perimeter to keep attackers out.
Correct answer: Assuming breach and verifying each access request as if it originates from an open network.
Zero Trust Architecture is built on the principle of "never trust, always verify." It assumes that the network is always hostile and that an attacker may already be present. Therefore, every access request, regardless of its origin (inside or outside the traditional perimeter), must be explicitly authenticated and authorized before access is granted.
Question 54: A security architect is using the DREAD model to prioritize threats identified for a critical system. A specific vulnerability is easy to discover and exploit, but it affects only a small, non-critical user group and causes minimal damage. Which DREAD component would result in the LOWEST score for this vulnerability?
- Affected Users & Damage (Correct answer)
- Exploitability
- Discoverability
- Reproducibility
Correct answer: Affected Users & Damage
The DREAD model rates threats based on five categories: Damage, Reproducibility, Exploitability, Affected Users, and Discoverability. In the given scenario, the vulnerability is easy to discover, reproduce, and exploit, which would lead to high scores in those categories. However, since it affects few users and causes minimal harm, the 'Affected Users' and 'Damage' components would receive the lowest scores, thus lowering the overall priority of the threat.
Question 55: A security architect is designing a system for a financial institution that must comply with the Sarbanes-Oxley Act (SOX). A primary objective is to align IT processes with business goals and ensure robust internal controls over financial reporting. Which of the following governance frameworks is MOST suitable for achieving this objective?
- ISO/IEC 27001
- ITIL (Information Technology Infrastructure Library)
- NIST Cybersecurity Framework (CSF)
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a comprehensive framework for the governance and management of enterprise IT. It is specifically designed to bridge the gap between technical issues, business risks, and control requirements, making it highly suitable for achieving compliance with regulations like SOX that require strong internal controls and alignment between IT and business objectives. While other frameworks are useful, COBIT's core focus is on governance and its link to business goals.
Question 56: Which DNS security extension provides cryptographic authentication of DNS responses to prevent cache poisoning attacks?
- DNS sinkholing
- DNS over HTTPS (DoH)
- DNSSEC (Correct answer)
- Split-horizon DNS
Correct answer: DNSSEC
DNSSEC adds digital signatures to DNS records, allowing resolvers to verify the authenticity and integrity of DNS responses and prevent cache poisoning.
Question 57: What is the principle of "least privilege" in security design?
- Limiting access rights to the minimum necessary for a role (Correct answer)
- Assigning users the highest possible permissions
- Disabling user authentication entirely
- Ensuring all users have administrative access
Correct answer: Limiting access rights to the minimum necessary for a role
The principle of "least privilege" dictates that users, programs, or processes should only be granted the absolute minimum permissions required to perform their legitimate functions. This minimizes the potential damage if an account is compromised, as an attacker would have limited access.
Question 58: An architect needs to protect BGP routing infrastructure from route hijacking. Which security control BEST addresses this threat?
- Deploying OSPF instead of BGP
- Implementing Resource Public Key Infrastructure (RPKI) with Route Origin Authorization (Correct answer)
- Using NAT on all edge routers
- Enabling VLAN tagging on peering interfaces
Correct answer: Implementing Resource Public Key Infrastructure (RPKI) with Route Origin Authorization
RPKI with Route Origin Authorization (ROA) cryptographically validates that BGP route announcements originate from authorized Autonomous Systems, mitigating route hijacking.
Question 59: A company is adopting The Open Group Architecture Framework (TOGAF) for its enterprise architecture. To ensure security is embedded throughout the process, the security architect recommends integrating security activities into each phase of the Architecture Development Method (ADM). During which ADM phase would the architect primarily define the security requirements for data and applications?
- Phase C: Information Systems Architectures (Correct answer)
- Phase B: Business Architecture
- Phase A: Architecture Vision
- Phase D: Technology Architecture
Correct answer: Phase C: Information Systems Architectures
Within the TOGAF Architecture Development Method (ADM), Phase C is focused on Information Systems Architectures, which is divided into two sub-phases: Data Architecture and Application Architecture. It is in this phase that the specific security requirements and controls related to how data is stored, managed, and accessed, and how applications should be designed securely, are developed.
Question 60: The concept of "defense in depth" relies on which of the following?
- Multiple redundant layers of security controls (Correct answer)
- A single strong layer of defense
- Physical security alone
- A focus on network security only
Correct answer: Multiple redundant layers of security controls
"Defense in depth" is a cybersecurity strategy that employs a series of overlapping and redundant security controls to protect information and systems. If one layer of defense fails, subsequent layers are in place to detect and prevent an attack, providing a more robust security posture.
Question 61: Which network security architecture principle involves placing systems in separate security zones to limit the blast radius of a breach?
- Port mirroring
- Bandwidth throttling
- Network segmentation (Correct answer)
- Protocol filtering
Correct answer: Network segmentation
Network segmentation divides a network into isolated zones so that a compromise in one zone cannot directly spread to others, limiting the breach's blast radius.
Question 62: What is the purpose of a digital signature?
- To encrypt data
- To ensure anonymity
- To verify the authenticity and integrity of a message (Correct answer)
- To generate a session key
Correct answer: To verify the authenticity and integrity of a message
A digital signature uses cryptographic techniques to provide assurance about the origin and integrity of a digital message or document. It verifies that the message has not been altered since it was signed and confirms the identity of the signer, ensuring non-repudiation.
Question 63: When designing network security architecture, which concept ensures that only the minimum necessary network traffic is permitted between zones by default?
- Default deny (implicit deny) policy (Correct answer)
- Stateful inspection only
- Default allow with logging
- Application-layer awareness
Correct answer: Default deny (implicit deny) policy
A default deny (implicit deny) policy blocks all traffic not explicitly permitted by firewall rules, ensuring attackers cannot exploit undefined or forgotten rule gaps.
Question 64: A financial services company is architecting a new cloud-native application. The security architect must ensure that sensitive customer data is protected both when stored in cloud object storage and when transmitted between microservices. Which combination of cryptographic solutions BEST addresses this requirement?
- IPsec for all data communication and TDE for the database.
- Asymmetric key encryption for all data states.
- SSL for data at rest and SSH for data in transit.
- TLS for data in transit and AES-256 for data at rest. (Correct answer)
Correct answer: TLS for data in transit and AES-256 for data at rest.
The question requires protection for two distinct data states: data at rest (stored in object storage) and data in transit (transmitted between services). Transport Layer Security (TLS) is the standard protocol for encrypting data in transit over a network. Advanced Encryption Standard (AES) with a 256-bit key is a widely adopted, strong symmetric algorithm for encrypting data at rest. This combination directly and effectively addresses both requirements of the scenario.
Question 65: Which of the following is used to determine the likelihood and impact of a risk?
- Both A and B
- Quantitative analysis (Correct answer)
- Qualitative analysis (Correct answer)
Correct answer: Quantitative analysis
Both quantitative and qualitative analysis are used to determine the likelihood and impact of a risk. Qualitative analysis uses descriptive terms (e.g., high, medium, low) for impact and likelihood, while quantitative analysis assigns numerical values and probabilities, often leading to a monetary value of risk.
Question 66: Which network architecture design pattern uses a bastion host to provide controlled administrative access to systems in a protected network segment?
- Honeynet
- Proxy server
- Screened subnet
- Jump server (jump box) (Correct answer)
Correct answer: Jump server (jump box)
A jump server (jump box) is a hardened, monitored bastion host that administrators must connect through to reach systems in restricted segments, providing an audited single point of entry.
Question 67: An ISSAP candidate is reviewing a network design that uses out-of-band (OOB) management. What is the PRIMARY security benefit of OOB management?
- It eliminates the need for encrypted management protocols like SSH
- It reduces latency for production traffic
- It isolates management traffic from production traffic, preserving access during attacks or outages (Correct answer)
- It automatically patches network devices when new firmware is available
Correct answer: It isolates management traffic from production traffic, preserving access during attacks or outages
Out-of-band management uses a separate network path for administrative access, ensuring that management connectivity is preserved even when production network paths are congested or under attack.
Question 68: When architecting a cryptographic solution for a multi-cloud environment, what is the most significant challenge a security architect must address regarding key management?
- Meeting FIPS 140-2 validation requirements for all keys.
- Ensuring low latency for cryptographic operations.
- Selecting algorithms that are supported by all cloud providers.
- Maintaining consistent key management policies and control across different providers. (Correct answer)
Correct answer: Maintaining consistent key management policies and control across different providers.
Each cloud service provider (CSP) has its own native key management service (KMS) with different APIs, policies, and capabilities. In a multi-cloud architecture, maintaining a consistent and centralized approach to key management policies, access control, and auditing becomes a major challenge. An architect must decide between using native tools, which leads to fragmented control, or implementing a third-party or hybrid KMS to achieve uniform governance across all cloud environments.
Question 69: A security architect is evaluating a proposal for a new enterprise-wide key management system. A key requirement is to prevent a single administrator from having complete control over the cryptographic keys, thereby preventing a single point of compromise. Which architectural concept should the architect ensure is implemented?
- Hardware Security Module (HSM) clustering
- Centralized key generation
- Key escrow
- Split knowledge and separation of duties (Correct answer)
Correct answer: Split knowledge and separation of duties
Split knowledge and separation of duties are core principles in key management that ensure no single person has unilateral access to or control over the entire key management process. Split knowledge involves dividing a key or access to keys among multiple individuals, while separation of duties ensures that different stages of the key lifecycle (e.g., generation, use, revocation) are controlled by different people or roles. This prevents a single compromised administrator from compromising the entire cryptographic system.
Question 70: When modeling a security architecture, a primary goal is to ensure that every security control can be directly traced back to a specific business driver or requirement. This principle of traceability is a core tenet of which security architecture framework?
- TOGAF
- STRIDE
- SABSA (Correct answer)
- Zachman Framework
Correct answer: SABSA
A fundamental principle of the SABSA framework is traceability. It ensures that all security decisions, controls, and services are directly linked to and derived from the business's goals, objectives, and risk appetite. This creates a clear and auditable chain from the strategic business context down to the operational security mechanisms.
Question 71: What is Single Sign-On (SSO) in the context of identity federation?
- A method to enhance password strength
- A way to replicate user accounts
- A tool for monitoring user activities
- A system that allows users to authenticate once and access multiple systems (Correct answer)
Correct answer: A system that allows users to authenticate once and access multiple systems
Single Sign-On (SSO) is a core concept in identity federation, enabling users to authenticate their identity once with an identity provider. After this initial authentication, they can then access multiple independent applications or services without needing to re-enter their credentials for each one. This significantly improves user experience and reduces the administrative burden of managing multiple passwords.
Question 72: To be most effective and least costly, a security architect should recommend that threat modeling be performed during which phase of the Secure Software Development Lifecycle (SSDLC)?
- Maintenance
- Design (Correct answer)
- Testing
- Deployment
Correct answer: Design
Threat modeling is most effective and cost-efficient when performed during the Design phase of the SSDLC. Identifying potential threats and architectural flaws at this early stage allows for security controls to be built into the system's blueprint, preventing expensive and time-consuming remediation that would be required if these issues were found later during testing or after deployment.
Question 73: A company operates a large, multi-cloud environment and is struggling to maintain a consistent security baseline. The security team needs a tool that can continuously scan cloud infrastructure configurations across AWS, Azure, and GCP to detect misconfigurations, compliance violations, and security risks in real-time. Which category of security tool is specifically designed for this purpose?
- Cloud Workload Protection Platform (CWPP)
- Next-Generation Firewall (NGFW)
- Cloud Security Posture Management (CSPM) (Correct answer)
- Security Information and Event Management (SIEM)
Correct answer: Cloud Security Posture Management (CSPM)
Cloud Security Posture Management (CSPM) tools are designed to provide visibility and continuous monitoring of cloud infrastructure. They automatically detect and alert on misconfigurations, policy violations, and compliance risks by comparing the current state of cloud resources against security best practices and compliance frameworks. In contrast, a CWPP focuses on protecting the individual workloads (like VMs and containers) running in the cloud.
Question 74: An organization has discovered that numerous employees are using unauthorized SaaS applications for business purposes, creating a significant 'shadow IT' problem. A security architect needs to recommend a solution that provides visibility into all cloud services in use, enforces data loss prevention (DLP) policies, and offers threat protection for sanctioned and unsanctioned applications. Which of the following is the MOST appropriate architectural component to address these requirements?
- Zero Trust Network Access (ZTNA) Controller
- Cloud Access Security Broker (CASB) (Correct answer)
- Secure Web Gateway (SWG)
- Web Application Firewall (WAF)
Correct answer: Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is specifically designed to address the security gaps created by cloud service usage, including shadow IT. A CASB sits between an organization's on-premises infrastructure and a cloud provider's infrastructure to enforce security policies as users access cloud-based resources. Key functions include discovering all cloud apps in use (sanctioned and unsanctioned), applying DLP policies to data in transit and at rest, and protecting against cloud-based threats.
Question 75: When designing a federated identity solution using Security Assertion Markup Language (SAML), what is the primary role of the Identity Provider (IdP)?
- To authenticate the user and issue a security assertion containing identity information. (Correct answer)
- To host the application or resource the user wants to access.
- To consume identity assertions and grant or deny access to a resource.
- To provide a centralized repository for storing user passwords and attributes.
Correct answer: To authenticate the user and issue a security assertion containing identity information.
In a SAML federation, the Identity Provider (IdP) is the entity responsible for authenticating the user and, upon successful authentication, creating a security assertion (a SAML token) that contains information about the user's identity and attributes. This assertion is then sent to the Service Provider (SP), which consumes it to make an authorization decision. The SP hosts the resource. While an IdP uses a directory, its primary role in the federation is authentication and assertion issuance.
Question 76: When conducting a network security architecture review, an architect evaluates trust zones. Which factor is MOST critical when defining trust zone boundaries?
- The physical location of network switches
- The age and model of network hardware in each segment
- The number of users accessing each zone
- The sensitivity of data and systems within the zone and the risk of interconnection (Correct answer)
Correct answer: The sensitivity of data and systems within the zone and the risk of interconnection
Trust zone boundaries should be defined by the sensitivity of assets and data contained within and the risk posed by allowing traffic between zones, ensuring high-value assets are maximally isolated.
Question 77: When architecting a baseline security configuration for new servers, the primary goal is to reduce the attack surface. Which of the following actions is the MOST fundamental and effective first step in achieving this goal?
- Enforcing a complex password policy
- Enabling full-disk encryption
- Removing all non-essential services, software, and ports (Correct answer)
- Implementing a host-based intrusion prevention system (HIPS)
Correct answer: Removing all non-essential services, software, and ports
The most fundamental principle of system hardening and reducing the attack surface is to remove or disable all functionality that is not strictly necessary for the system's business purpose. This includes uninstalling unused software packages, disabling unneeded services, and closing unnecessary network ports, which directly eliminates potential vectors an attacker could exploit. The other options are important security controls but are applied to protect the remaining services, not to reduce the number of services themselves.
Question 78: When designing a secure network infrastructure, which protocol suite is specifically designed to provide confidentiality, integrity, and authentication for data at the IP packet level, securing communications between two endpoints across a network?
- Internet Protocol Security (IPsec) (Correct answer)
- Secure File Transfer Protocol (SFTP)
- Transport Layer Security (TLS)
- Secure Shell (SSH)
Correct answer: Internet Protocol Security (IPsec)
IPsec operates at the network layer (Layer 3) and is designed to secure IP communications by authenticating and encrypting each IP packet in a data stream. It can be used to create secure VPNs and protect traffic between servers. TLS operates at the transport layer, securing application-to-application communication, while SSH and SFTP are application-layer protocols for secure remote access and file transfer, respectively.
Question 79: A global corporation with major offices in North America, Europe, and Asia needs to establish a 24/7 security monitoring capability. The goal is to handle common alerts locally within each region for efficiency, while escalating complex, novel, or widespread threats to a central team of highly skilled experts for in-depth analysis and coordination. Which Security Operations Center (SOC) model BEST fits this architectural requirement?
- A distributed SOC with fully independent regional teams.
- A virtual SOC (VSOC) leveraging geographically dispersed analysts without a central command.
- A co-managed SOC where a third-party manages all Tier 1 analysis globally.
- A tiered or hierarchical SOC with regional Tier 1/2 teams and a central Tier 3 command SOC. (Correct answer)
Correct answer: A tiered or hierarchical SOC with regional Tier 1/2 teams and a central Tier 3 command SOC.
A tiered or hierarchical SOC model is the most suitable architecture. It allows regional teams (Tier 1/2) to handle the high volume of routine alerts and perform initial triage, providing rapid response within their respective time zones. [15] Complex, severe, or cross-regional incidents are escalated to a central command SOC (Tier 3) staffed with senior analysts, threat hunters, and forensic experts who can perform deeper analysis and coordinate a global response. [6] This balances local efficiency with centralized expertise.
Question 80: A security architect is tasked with developing a security architecture that is tightly aligned with business objectives and integrates risk management throughout the entire lifecycle of enterprise systems. Which of the following frameworks is MOST suitable for this purpose due to its business-driven approach?
- Zachman Framework
- TOGAF
- STRIDE
- SABSA (Correct answer)
Correct answer: SABSA
SABSA (Sherwood Applied Business Security Architecture) is specifically designed as a business-driven security architecture framework. It starts by analyzing business requirements and uses a risk-based approach to develop a security architecture that supports business goals. TOGAF is a general enterprise architecture framework, Zachman is an ontology for organizing artifacts, and STRIDE is a threat modeling methodology, not a comprehensive architecture framework.
Question 81: What is a residual risk?
- The total cost of risk mitigation
- The risk identified during initial risk assessment
- The likelihood of a threat exploiting a vulnerability
- The risk remaining after implementing security measures (Correct answer)
Correct answer: The risk remaining after implementing security measures
Residual risk refers to the level of risk that remains after all planned and implemented security controls and mitigation strategies have been applied. It's the risk that an organization accepts because it cannot be entirely eliminated or the cost of further mitigation outweighs the benefit.
Question 82: An organization is deploying a new application using a microservices architecture running in containers managed by Kubernetes. The security architect is concerned about unauthorized communication between different microservices (pods) once an attacker compromises a single container. Which of the following Kubernetes-native controls is the MOST effective for enforcing a Zero Trust policy and restricting this lateral movement?
- Using a secrets management vault
- Applying default-deny Network Policies (Correct answer)
- Enforcing strict Role-Based Access Control (RBAC) on the API server
- Implementing Pod Security Policies (PSPs)
Correct answer: Applying default-deny Network Policies
Kubernetes Network Policies are the primary native mechanism for controlling traffic flow at the IP address or port level (OSI layer 3 or 4) between pods. By implementing a default-deny policy and then explicitly allowing only required communication paths between microservices, an architect can enforce a Zero Trust, least-privilege network model. This directly limits an attacker's ability to move laterally within the cluster.
Question 83: Which cryptographic algorithm is considered asymmetric?
- AES (Advanced Encryption Standard)
- DES (Data Encryption Standard)
- RSA (Rivest-Shamir-Adleman) (Correct answer)
- 3DES (Triple DES)
Correct answer: RSA (Rivest-Shamir-Adleman)
RSA (Rivest-Shamir-Adleman) is a widely used public-key (asymmetric) cryptographic algorithm, meaning it uses a pair of mathematically linked keys: a public key for encryption and a private key for decryption. This allows secure communication without prior sharing of a secret key.
Question 84: In a secure network architecture, which technique is used to prevent a compromised VLAN from sending tagged frames to unauthorized VLANs?
- Using private VLANs for all segments
- Implementing 802.1X port authentication only
- VLAN hopping prevention via disabling DTP and setting native VLANs (Correct answer)
- Enabling BPDU guard on all trunk ports
Correct answer: VLAN hopping prevention via disabling DTP and setting native VLANs
Disabling Dynamic Trunking Protocol (DTP) and configuring a dedicated, unused native VLAN prevents double-tagging and switch spoofing attacks that enable VLAN hopping.
Question 85: What does the principle of "fail-safe defaults" emphasize?
- Systems should default to the most permissive state
- Systems should fail in a secure state, restricting access (Correct answer)
- Users should determine default settings
- No restrictions should be applied during failure
Correct answer: Systems should fail in a secure state, restricting access
The principle of "fail-safe defaults" ensures that when a system component fails or an error occurs, it defaults to a secure, restrictive state rather than an open or permissive one. This prevents unauthorized access or data exposure during system malfunctions, maintaining security.
Question 86: An organization is migrating its data center to a hybrid cloud model. A security architect is tasked with defining security responsibilities for the new Infrastructure as a Service (IaaS) environment. According to the shared responsibility model, which of the following is the customer's primary responsibility?
- Managing virtualization software (the hypervisor).
- Configuring operating system patches and managing user access controls. (Correct answer)
- Ensuring the security of the cloud provider's hardware.
- Securing the physical data center and network infrastructure.
Correct answer: Configuring operating system patches and managing user access controls.
In an IaaS model, the cloud provider is responsible for the security 'of' the cloud (physical infrastructure, network, hypervisor). The customer is responsible for security 'in' the cloud, which includes securing the guest operating systems, data, applications, identity, and access management. Therefore, configuring OS patches and managing user access falls squarely on the customer.
Question 87: A large, multinational corporation is designing an access control architecture for a new, highly dynamic environment. The system must support fine-grained access decisions based on a user's role, their geographic location, the time of day, and the data sensitivity of the resource being accessed. Traditional access control models are proving too static. Which of the following access control models would be MOST suitable for this architecture?
- Discretionary Access Control (DAC)
- Attribute-Based Access Control (ABAC) (Correct answer)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC)
Correct answer: Attribute-Based Access Control (ABAC)
Attribute-Based Access Control (ABAC) is the most suitable model because it makes access decisions based on a combination of attributes of the user, resource, action, and environment. This allows for the creation of dynamic, context-aware policies that can handle the complexity described in the scenario (role, location, time, data sensitivity). RBAC is limited to user roles, while DAC is user-managed and MAC is based on security labels, neither of which provide the required flexibility.
Question 88: Where should an Intrusion Detection System (IDS) sensor be placed to detect attacks targeting a public-facing web server in a DMZ?
- Between the external firewall and the DMZ (Correct answer)
- On the internal LAN segment only
- Between the internal network and the DMZ firewall
- Behind the web server on the database segment
Correct answer: Between the external firewall and the DMZ
Placing an IDS sensor between the external firewall and the DMZ allows it to inspect inbound traffic destined for DMZ services before it reaches those servers.
Question 89: Which type of cryptography uses the same key for encryption and decryption?
- Public key infrastructure (PKI)
- Asymmetric cryptography
- Hash functions
- Symmetric cryptography (Correct answer)
Correct answer: Symmetric cryptography
Symmetric cryptography, also known as secret-key cryptography, uses a single, shared secret key for both encrypting and decrypting data. Both the sender and receiver must possess this identical key, making secure key distribution a critical challenge.
CISSP-ISSAP: Information Systems Security Architecture Professional
The CISSP-ISSAP is an advanced ISC2 concentration certification validating the expertise of senior security professionals in designing and managing enterprise security architectures across governance, infrastructure, and identity domains. Candidates must hold an active CISSP and demonstrate two years of experience in ISSAP domains.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds