← All CISSP Flashcard Decks

Security Architecture Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Architecture flashcards as text
  1. Which security architecture principle ensures that a compromised component cannot be used to gain unauthorized access to other components?

    Answer: Isolation and containment

    Isolation and containment limits the blast radius of a compromise by preventing lateral movement between components.

  2. In the Zachman Framework, which column addresses the question 'How does the system work?'

    Answer: Function column

    The Function column in the Zachman Framework addresses processes and how the system operates.

  3. A system that defaults to denying access when an error occurs is implementing which security principle?

    Answer: Fail-secure

    Fail-secure (or fail-safe) ensures systems default to a secure state — denying access — upon failure.

  4. Which of the following best describes a Reference Monitor?

    Answer: An abstract machine that mediates all access between subjects and objects

    A Reference Monitor is an abstract machine concept that intercepts every access attempt between subjects and objects to enforce policy.

  5. The Clark-Wilson integrity model primarily addresses which type of environment?

    Answer: Commercial transaction integrity

    Clark-Wilson was designed for commercial environments, ensuring data integrity through well-formed transactions and separation of duties.

  6. Which architectural component validates that all security controls are properly tested and verified before deployment?

    Answer: Trusted Computing Base (TCB)

    The Trusted Computing Base encompasses all hardware, software, and firmware that enforce the system security policy.

  7. In a zero trust architecture, what is the role of the Policy Decision Point (PDP)?

    Answer: Evaluates access requests against policy and grants or denies access

    The PDP evaluates access requests using identity, context, and policy to make authorization decisions in a zero trust model.