iSAQB Certified Professional for Software Architecture (CPSA) Exam — Questions and Answers
Question 1: When two quality attributes conflict, what is the RECOMMENDED approach for an architect?
- Always prioritize security over all other attributes
- Make the conflict explicit and let stakeholders decide based on business priorities (Correct answer)
- Choose the attribute mentioned first in requirements
- Implement both attributes fully regardless of cost
Correct answer: Make the conflict explicit and let stakeholders decide based on business priorities
Architects must surface trade-offs transparently so stakeholders can make informed prioritization decisions.
Question 2: In the context of the CPSA framework, which architectural pattern directly supports the 'Open/Closed Principle' by allowing new behavior to be added without modifying the core?
- Shared Database Pattern
- Active Record Pattern
- Monolith-First Pattern
- Plugin / Microkernel Architecture (Correct answer)
Correct answer: Plugin / Microkernel Architecture
Microkernel (Plugin) architecture keeps a minimal stable core and allows new features to be added as plugins, so the core remains closed for modification but open for extension.
Question 3: In a layered architecture, which rule governs how building blocks in different layers may interact?
- Blocks may only depend on blocks in the same or lower layers (Correct answer)
- Blocks in lower layers may call upper layers via callbacks
- Blocks must communicate only through a central bus
- Blocks may communicate freely across any layer
Correct answer: Blocks may only depend on blocks in the same or lower layers
The layering rule requires that dependencies flow downward — a block may use blocks in the same layer or layers below it.
Question 4: Which strategy best addresses consistency of error responses across all services in a microservices architecture?
- Letting each service define its own error format
- Using HTTP 200 for all responses and embedding status in the body
- Defining a shared error response schema and enforcing it via an API gateway (Correct answer)
- Relying on client-side error normalization only
Correct answer: Defining a shared error response schema and enforcing it via an API gateway
A shared error response schema enforced at the API gateway ensures uniform error handling that clients can rely on regardless of which backend service responded.
Question 5: Which trade-off is a direct consequence of applying the microservices architectural style compared to a monolith?
- Simpler deployment pipeline but higher runtime coupling
- Stronger data consistency guarantees across all services
- Increased operational complexity in exchange for independent deployability and scalability (Correct answer)
- Lower latency for all inter-component calls due to network proximity
Correct answer: Increased operational complexity in exchange for independent deployability and scalability
Microservices improve independent scalability and deployment but introduce distributed systems challenges such as network latency, eventual consistency, and complex operations.
Question 6: Which tool is most commonly associated with Active Directory enumeration and attack path visualization during internal penetration tests?
- Burp Suite
- BloodHound (Correct answer)
- OpenVAS
- Metasploit
Correct answer: BloodHound
BloodHound collects AD data via SharpHound and visualizes attack paths, identifying the shortest path to Domain Admin through ACL abuse, group memberships, and trust relationships.
Question 7: A software architect is designing an online retail platform. The system needs to react to various business occurrences—such as 'order placed,' 'payment processed,' or 'item shipped'—in a highly decoupled and asynchronous manner. Multiple downstream systems (e.g., inventory, notifications, analytics) need to be notified of these occurrences without the upstream service being aware of them. Which architectural style best supports these requirements?
- Client-Server
- Event-Driven Architecture (Correct answer)
- Layered Architecture
- Monolithic Architecture
Correct answer: Event-Driven Architecture
Event-Driven Architecture (EDA) is designed around the production, detection, and consumption of events. This style allows for highly decoupled components (producers and consumers) that communicate asynchronously. It is perfect for scenarios where an action in one part of the system needs to trigger workflows in multiple, unrelated parts of the system without creating direct dependencies.
Question 8: Which Nmap scan type is most appropriate when ICMP is blocked by a firewall but you need to discover live hosts on a subnet?
- ICMP echo scan (-PE)
- TCP SYN ping scan (-PS) (Correct answer)
- UDP ping scan (-PU)
- ARP ping scan (-PR)
Correct answer: TCP SYN ping scan (-PS)
TCP SYN ping (-PS) sends SYN packets to common ports to detect live hosts when ICMP is filtered by perimeter firewalls.
Question 9: A new developer is joining the team and needs to understand the static organization of the source code, including its decomposition into modules, subsystems, and the dependencies between them. Which of the following views would be the MOST effective starting point for this developer?
- The Runtime View
- The Logical View
- The Deployment View
- The Building Block View (Correct answer)
Correct answer: The Building Block View
The Building Block View (also known as the component or development view) shows the static structure and organization of the software. It illustrates how the system is broken down into components or modules and how they relate to each other, which is essential for a developer to understand the codebase structure.
Question 10: A software architect is reviewing a legacy system and finds that business logic is spread across the UI, service, and database layers. Which architectural principle is being violated?
- Separation of concerns (Correct answer)
- Single responsibility at the class level
- Interface segregation
- Open/Closed principle
Correct answer: Separation of concerns
Separation of concerns requires that distinct responsibilities be assigned to distinct layers or components; mixing business logic across layers violates this principle.
Question 11: A team standardizes all inter-service timeouts to 500ms via a shared client library. Which cross-cutting quality attribute does this primarily protect?
- Resilience, by preventing resource exhaustion from slow dependencies (Correct answer)
- Maintainability, by reducing code duplication
- Throughput, by increasing the number of simultaneous requests
- Portability, by abstracting infrastructure details
Correct answer: Resilience, by preventing resource exhaustion from slow dependencies
Standardized timeouts prevent threads from blocking indefinitely on slow services, protecting system resilience by releasing resources promptly.
Question 12: When should an architect choose to document a decision as an ADR versus simply commenting in the code?
- ADRs are required only for decisions made by external consultants
- Code comments are always sufficient for any architectural decision
- ADRs are only for rejected options
- ADRs are warranted when the decision has significant architectural impact, cross-cutting consequences, or is likely to be questioned later (Correct answer)
Correct answer: ADRs are warranted when the decision has significant architectural impact, cross-cutting consequences, or is likely to be questioned later
ADRs capture high-impact decisions with context and rationale that code comments cannot adequately convey.
Question 13: Why is documenting the rationale for building block decomposition decisions considered important in arc42?
- It is required by all agile methodologies
- It satisfies compliance auditing requirements automatically
- It replaces the need for interface documentation
- It allows future architects to understand trade-offs and avoid re-litigating settled decisions (Correct answer)
Correct answer: It allows future architects to understand trade-offs and avoid re-litigating settled decisions
Recording rationale preserves the reasoning behind decomposition choices so future teams understand constraints and avoid repeating past analysis.
Question 14: In the context of software architecture, which of the following is an example of a cross-cutting concern?
- Adding a new report for sales analytics.
- Implementing the user registration feature.
- Implementing system-wide logging for auditing and debugging. (Correct answer)
- Designing the product catalog database schema.
Correct answer: Implementing system-wide logging for auditing and debugging.
A cross-cutting concern is a feature or requirement that affects multiple modules or layers of an application, such as logging, security, or caching. User registration, database schema, and specific reports are typically encapsulated within specific modules and are not considered cross-cutting.
Question 15: In enterprise integration patterns, what is a 'canonical data model'?
- The XML schema for REST API responses
- The database schema used by the primary application
- A shared data format that all integrated systems use to avoid point-to-point format translations (Correct answer)
- A UML class diagram of the domain model
Correct answer: A shared data format that all integrated systems use to avoid point-to-point format translations
A canonical data model provides a common intermediate format, reducing the number of translators needed from N×(N-1) to 2×N in an N-system landscape.
Question 16: In a risk matrix, how is overall risk level typically determined?
- By averaging the team's subjective fear ratings for each risk
- By multiplying the probability of occurrence by the impact severity (Correct answer)
- By summing all identified risks regardless of probability
- By counting the number of components affected by the risk
Correct answer: By multiplying the probability of occurrence by the impact severity
Risk level = Probability × Impact; this formula gives a prioritized ranking so teams can focus effort on high-probability, high-impact risks first.
Question 17: Which arc42 section is the recommended place to document cross-cutting concepts such as security, logging, and error handling?
- Section 3 – System Scope and Context
- Section 5 – Building Block View
- Section 8 – Crosscutting Concepts (Correct answer)
- Section 12 – Glossary
Correct answer: Section 8 – Crosscutting Concepts
Arc42 Section 8 is dedicated to crosscutting concerns that apply uniformly across multiple parts of the system.
Question 18: A quality scenario specifying 'under normal operations' is describing which scenario component?
- Environment (Correct answer)
- Artifact
- Response
- Stimulus
Correct answer: Environment
The environment component of a quality scenario describes the operational context or state of the system when the stimulus occurs.
Question 19: Which of the following is NOT a typical step in the ATAM evaluation process?
- Writing unit tests for each component (Correct answer)
- Analyzing architectural approaches
- Generating a utility tree
- Presenting business drivers
Correct answer: Writing unit tests for each component
Writing unit tests is a development activity, not part of the ATAM evaluation process, which focuses on architectural analysis rather than implementation.
Question 20: In the context of building block design, what does 'stable dependency principle' prescribe?
- Stable blocks should depend on volatile blocks
- Blocks should avoid depending on external libraries
- All blocks should be equally stable
- Frequently changing blocks should depend on stable blocks (Correct answer)
Correct answer: Frequently changing blocks should depend on stable blocks
The Stable Dependency Principle states that dependencies should point toward more stable components to limit change propagation.
Question 21: An architect is defining a quality scenario for system availability. The scenario reads: 'Under normal operation, an unexpected database connection failure occurs.' Which essential component of a quality scenario is missing from this statement?
- Response and Response Measure (Correct answer)
- Source and Artifact
- Stimulus and Environment
- Artifact and Stimulus
Correct answer: Response and Response Measure
A complete quality scenario consists of six parts: source, stimulus, artifact, environment, response, and response measure. The provided statement includes the environment ('Under normal operation') and the stimulus ('an unexpected database connection failure occurs'). However, it fails to specify how the system should react (the response) and the measurable criteria for success (the response measure), such as 'the system logs the error and restores the connection within 5 seconds'.
Question 22: Which architectural quality attribute is most directly threatened when a system must integrate with many heterogeneous external systems?
- Usability
- Interoperability (Correct answer)
- Testability
- Deployability
Correct answer: Interoperability
Integrating with diverse external systems directly tests interoperability, requiring the architecture to manage varying protocols, data formats, and communication patterns.
Question 23: What is the key distinction between an architectural style and an architectural pattern?
- There is no practical difference; the terms are used interchangeably in the industry.
- A pattern describes the physical deployment view, while a style describes the logical component view.
- A style is a high-level, abstract concept about system organization, while a pattern is a concrete, reusable solution to a recurring problem within that style. (Correct answer)
- A style is a low-level solution for a specific coding problem, while a pattern is a high-level system structure.
Correct answer: A style is a high-level, abstract concept about system organization, while a pattern is a concrete, reusable solution to a recurring problem within that style.
An architectural style is a high-level, conceptual way of organizing a system (e.g., Client-Server, Event-Driven). An architectural pattern provides a more concrete, reusable solution to a common problem that often helps implement a style (e.g., MVC is a pattern often used within a Client-Server style). The key difference is the level of abstraction and scope.
Question 24: What is a 'facade' building block used for in software architecture?
- To provide a simplified interface to a complex set of subsystems (Correct answer)
- To persist data in a relational database
- To enforce security policies across subsystems
- To monitor runtime performance of other blocks
Correct answer: To provide a simplified interface to a complex set of subsystems
A facade provides a unified, simplified interface to a complex subsystem, hiding its internal complexity from clients.
Question 25: A system's audit requirement mandates that every data change be logged with a timestamp and user identity. This requirement primarily impacts which quality attribute?
- Throughput and performance
- Ease of initial installation
- Accountability and traceability (Correct answer)
- Portability across platforms
Correct answer: Accountability and traceability
Comprehensive audit logging directly supports accountability and traceability, enabling investigation of who changed what data and when.
Question 26: Which design principle is MOST directly related to the concept of an 'anti-corruption layer' in domain-driven design?
- Separation of Concerns (Correct answer)
- Single Responsibility Principle
- YAGNI
- Liskov Substitution Principle
Correct answer: Separation of Concerns
An anti-corruption layer separates different domain models or contexts, directly embodying Separation of Concerns by isolating external system concerns from internal domain logic.
Question 27: Event-Driven Architecture (EDA) most directly improves which architectural quality?
- Reduced infrastructure cost
- Temporal decoupling between producers and consumers (Correct answer)
- Simplified debugging and tracing
- Strong consistency across all components
Correct answer: Temporal decoupling between producers and consumers
EDA allows producers to emit events without waiting for consumers to process them, enabling components to operate and scale independently at different speeds.
Question 28: The 'response measure' part of a quality scenario defines:
- The component of the system being evaluated
- The quantifiable criterion used to evaluate whether the system met the quality goal (Correct answer)
- The operational context during the scenario
- The entity that initiates the quality event
Correct answer: The quantifiable criterion used to evaluate whether the system met the quality goal
The response measure provides a testable, quantitative or qualitative criterion for assessing the system's quality response.
Question 29: Which metric is computed as I = Ce / (Ca + Ce) and indicates the instability of a software package?
- Abstractness (A)
- Cyclomatic Complexity (CC)
- Distance from the Main Sequence (D)
- Instability (I) (Correct answer)
Correct answer: Instability (I)
Robert Martin's Instability metric I = Ce / (Ca + Ce) ranges from 0 (maximally stable) to 1 (maximally unstable), measuring a package's resilience to change.
Question 30: In iSAQB terminology, a 'building block' is best described as:
- A physical server or virtual machine
- A third-party library or framework
- A named, self-contained architectural element with defined responsibilities (Correct answer)
- A database table or schema
Correct answer: A named, self-contained architectural element with defined responsibilities
A building block is a named, self-contained architectural element with clearly defined responsibilities and interfaces.
Question 31: Which of the following describes the primary purpose of using a 'general scenario' when defining quality attributes?
- To measure the performance of the architecture after the system has been fully deployed.
- To provide a system-independent template or checklist to help elicit and specify concrete quality requirements. (Correct answer)
- To document the final, detailed, and system-specific quality requirements for implementation.
- To replace the need for functional requirements by focusing only on quality attributes.
Correct answer: To provide a system-independent template or checklist to help elicit and specify concrete quality requirements.
General scenarios are system-independent templates that describe a common type of stimulus and response for a particular quality attribute (like modifiability or security). They serve as a starting point or a checklist to guide architects and stakeholders in creating specific, context-relevant quality scenarios for their particular system. They are not the final detailed requirement themselves but a tool to create them.
Question 32: Which of the following BEST describes the architect's role in an agile project?
- Producing a complete upfront design before any code is written
- Attending only the initial sprint and the final release sprint
- Avoiding all technical decisions to preserve team autonomy
- Continuously collaborating with teams, making just-enough decisions, and enabling evolutionary design (Correct answer)
Correct answer: Continuously collaborating with teams, making just-enough decisions, and enabling evolutionary design
In agile contexts, architects collaborate continuously with teams, make decisions at the last responsible moment, and support evolutionary architecture rather than producing a complete upfront design.
Question 33: Which of the following best describes an 'architecturally significant requirement' (ASR)?
- A UI design requirement from the UX team
- A requirement that has a major impact on the system's architecture (Correct answer)
- A performance benchmark set by the operations team
- Any functional requirement defined by the product owner
Correct answer: A requirement that has a major impact on the system's architecture
ASRs are requirements with a measurable, significant impact on the architecture; they directly shape structural decisions.
Question 34: A software architect is designing a new e-commerce platform. The business stakeholders have mandated that the total budget for development and initial deployment cannot exceed $500,000 and the platform must launch before the holiday season in six months. How should the architect classify these two requirements?
- As technical risks
- As quality attributes
- As functional requirements
- As business constraints (Correct answer)
Correct answer: As business constraints
Fixed budget and schedule are classic examples of business constraints. They are non-technical decisions made by the business that severely limit the options available for the software architecture design. They are not quality attributes (like performance), functional requirements (what the system does), or technical risks (potential technology problems).
Question 35: An architect needs to create documentation for the operations team to plan server capacity and network configuration. Which architectural view is MOST suitable for communicating how software components are mapped to physical machines, servers, and other hardware nodes?
- Building Block View
- Context View
- Deployment View (Correct answer)
- Runtime View
Correct answer: Deployment View
The Deployment View is specifically designed to show the physical topology of the system, illustrating how software artifacts are deployed onto hardware nodes. This directly addresses the concerns of an operations team regarding infrastructure planning.
Question 36: Which approach is most appropriate when two critical quality goals appear mutually exclusive?
- Defer the decision until the project is nearly complete
- Analyze scenarios to find a design point that acceptably balances both goals (Correct answer)
- Always prioritize security over all other quality attributes
- Choose the goal that satisfies the most stakeholders by count
Correct answer: Analyze scenarios to find a design point that acceptably balances both goals
Scenario-based analysis helps architects find design solutions that achieve an acceptable balance rather than fully sacrificing either quality attribute.
Question 37: What does the term 'lateral movement' mean in the context of a penetration test?
- Escalating privileges on the initially compromised host
- Pivoting from an internal network to the internet
- Extracting data from a database server
- Moving from one compromised system to other systems in the network (Correct answer)
Correct answer: Moving from one compromised system to other systems in the network
Lateral movement refers to techniques used to progressively move through a network after initial compromise, accessing additional hosts and resources.
Question 38: What is the significance of the 'view' concept in software architecture documentation?
- A view represents the system from a particular stakeholder perspective, addressing specific concerns (Correct answer)
- A view is a database query result set displayed to end users
- A view is a GUI mockup created by UX designers for stakeholder approval
- A view is the architect's personal opinion about the system's design
Correct answer: A view represents the system from a particular stakeholder perspective, addressing specific concerns
An architectural view presents the system from the perspective of a specific set of concerns relevant to particular stakeholders, such as runtime behavior, deployment, or module structure.
Question 39: Which cross-cutting mechanism prevents a slow database query from degrading the responsiveness of unrelated read operations in the same service?
- Bulkhead pattern using separate thread pools or connection pools (Correct answer)
- Switching all queries to synchronous processing
- Increasing the global connection pool size
- Combining read and write operations into a single query
Correct answer: Bulkhead pattern using separate thread pools or connection pools
The bulkhead pattern isolates resources (threads or connections) for different operation types so that saturation in one pool does not starve another.
Question 40: Which of the following is a CORRECT way to express that Building Block A depends on Building Block B?
- A provides an interface that B implements
- B's required interface matches A's provided interface
- A's required interface matches B's provided interface (Correct answer)
- A and B share the same internal data model
Correct answer: A's required interface matches B's provided interface
A dependency from A to B means A requires a service that B provides — A's required interface is fulfilled by B's provided interface.
Question 41: What does the term 'architecture erosion' refer to in software development?
- The increasing divergence between the intended architecture and the implemented system (Correct answer)
- The reduction in system performance caused by hardware aging
- The removal of deprecated API endpoints from a system
- The gradual deletion of unused source code files over time
Correct answer: The increasing divergence between the intended architecture and the implemented system
Architecture erosion occurs when actual implementation gradually deviates from the planned architecture, often due to shortcuts, uncoordinated changes, or poor governance.
Question 42: According to the iSAQB curriculum, what is the primary purpose of defining and documenting cross-cutting concepts?
- To ensure the conceptual integrity and consistency of the architecture. (Correct answer)
- To satisfy legal and compliance requirements for auditing.
- To provide a complete component specification for third-party developers.
- To map business requirements directly to building blocks.
Correct answer: To ensure the conceptual integrity and consistency of the architecture.
Defining and documenting cross-cutting concepts helps ensure that overarching rules and decisions are applied consistently across the entire system. [7] This creates conceptual integrity (homogeneity), which is a critical factor in achieving the system's desired internal quality attributes, such as maintainability and reliability. [7, 8]
Question 43: An architect is designing a large-scale enterprise system with multiple services. The requirements state that every action that modifies data must be logged for auditing purposes, and every incoming request must be checked for valid authentication credentials. How are these two requirements best categorized?
- As core business logic for their respective services.
- As deployment view concerns to be handled by infrastructure.
- As specific quality attributes tied to reliability.
- As cross-cutting concepts that affect multiple services. (Correct answer)
Correct answer: As cross-cutting concepts that affect multiple services.
Authentication and audit logging are classic examples of cross-cutting concepts (or concerns) because their logic needs to be applied across many different modules or services in a system. [3, 4] They are not part of the core business logic of any single component (like calculating an order total) but are systemic, overarching functionalities. [3, 6] While they can be implemented in the infrastructure, their primary architectural classification is as cross-cutting concepts that require a deliberate design strategy.
Question 44: Which statement BEST describes the Open/Closed Principle?
- Public methods should be open while private methods remain closed
- Classes should be open for modification and closed for extension
- Software entities should be open for extension but closed for modification (Correct answer)
- Interfaces should be open to any implementation without restriction
Correct answer: Software entities should be open for extension but closed for modification
The Open/Closed Principle states that software entities should be open for extension (new behavior can be added) but closed for modification (existing code is not changed).
Question 45: Which of the following BEST illustrates a violation of the Dependency Inversion Principle?
- A module depends on an abstract factory
- A high-level business logic class directly instantiates a specific database class (Correct answer)
- A class implements two different interfaces
- A method returns an interface type rather than a concrete type
Correct answer: A high-level business logic class directly instantiates a specific database class
When a high-level module directly instantiates a concrete low-level class (e.g., a specific database), it creates a hard dependency on implementation details, violating DIP.
Question 46: A team is developing a system for processing financial transactions. A key quality attribute is security. Which scenario best represents a concrete, testable security requirement?
- An external actor with no credentials attempts to access a customer's transaction history via a public API endpoint; the system rejects the request and logs the attempt within 100ms. (Correct answer)
- The system must prevent unauthorized access to customer data.
- All data transmission must be encrypted to ensure confidentiality.
- The system should be designed with security best practices in mind.
Correct answer: An external actor with no credentials attempts to access a customer's transaction history via a public API endpoint; the system rejects the request and logs the attempt within 100ms.
This is the only option structured as a complete quality scenario. It specifies the source (external actor), stimulus (attempts to access data), artifact (public API endpoint), response (rejects and logs), and response measure (within 100ms). The other options are vague goals or general statements that lack the specific, measurable, and testable components of a well-defined scenario.
iSAQB Certified Professional for Software Architecture (CPSA) Exam
The iSAQB CPSA exam certifies software architects in architectural fundamentals, designing building blocks, cross-cutting concerns, quality attributes, architectural patterns, integration, and architecture evaluation.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds