Cross-cutting Concepts Flashcards
7 cards from real CPSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cross-cutting Concepts flashcards as text
A CPSA architect documents that all services must emit metrics in the Prometheus exposition format. This is an example of enforcing which type of cross-cutting decision?
Answer: Observability standard
Mandating a common metrics format is an observability standard — a cross-cutting decision that ensures all services are uniformly monitorable.
Which technique most effectively prevents SQL injection as a cross-cutting security concern in a data access layer?
Answer: Parameterized queries / prepared statements enforced in a shared data access library
Parameterized queries separate SQL code from data, eliminating injection risk when enforced centrally in a shared data access library across all services.
In CPSA, Aspect-Oriented Programming (AOP) is most directly associated with implementing which type of concern?
Answer: Cross-cutting concerns such as logging and security
AOP was specifically designed to modularize cross-cutting concerns like logging, security, and transaction management that would otherwise be scattered throughout the codebase.
Which cross-cutting practice ensures that a system can reconstruct its state after a failure by replaying events?
Answer: Event sourcing
Event sourcing stores every state change as an immutable event, allowing the system to replay events to reconstruct any past or current state after a failure.
A team standardizes all inter-service timeouts to 500ms via a shared client library. Which cross-cutting quality attribute does this primarily protect?
Answer: Resilience, by preventing resource exhaustion from slow dependencies
Standardized timeouts prevent threads from blocking indefinitely on slow services, protecting system resilience by releasing resources promptly.
Which cross-cutting architectural decision governs how personal data is anonymized or deleted across all services when a user invokes GDPR right-to-erasure?
Answer: A data lifecycle policy enforced by a central privacy service or event
A centrally enforced data lifecycle policy ensures consistent, auditable erasure across all services when a user's right-to-erasure request is processed.
When implementing rate limiting as a cross-cutting concern in an API gateway, what is the most important state-sharing consideration for a horizontally scaled gateway?
Answer: Rate limit counters must be stored in a shared external store (e.g., Redis) so all instances see the same count
Without a shared counter store, each gateway instance tracks limits independently, allowing clients to exceed the total rate limit by routing to different instances.