CISSP-ISSAP: Information Systems Security Architecture Professional — Questions and Answers
Question 1: In a traditional three-tier network architecture, what is the primary security purpose of a DMZ (Demilitarized Zone)?
- To aggregate logs from all internal systems
- To isolate publicly accessible services from the internal network (Correct answer)
- To terminate VPN connections from remote users
- To host internal databases securely
Correct answer: To isolate publicly accessible services from the internal network
The DMZ hosts publicly accessible services (e.g., web servers) while isolating them from the internal network, so external threats cannot directly reach internal resources.
Question 2: When modeling a security architecture, a primary goal is to ensure that every security control can be directly traced back to a specific business driver or requirement. This principle of traceability is a core tenet of which security architecture framework?
- TOGAF
- Zachman Framework
- STRIDE
- SABSA (Correct answer)
Correct answer: SABSA
A fundamental principle of the SABSA framework is traceability. It ensures that all security decisions, controls, and services are directly linked to and derived from the business's goals, objectives, and risk appetite. This creates a clear and auditable chain from the strategic business context down to the operational security mechanisms.
Question 3: What does the term identity provider (IdP) mean in a federated identity system?
- A database where user activities are logged
- A firewall that filters user requests
- A service that authenticates users and provides identity information (Correct answer)
- A user who manages credentials
Correct answer: A service that authenticates users and provides identity information
An Identity Provider (IdP) is a trusted entity in a federated identity system responsible for authenticating a user's identity. Once authenticated, the IdP issues an assertion or token containing the user's identity information to a service provider. This allows the user to access resources on the service provider without directly sharing their credentials with it.
Question 4: What is the primary function of a hash algorithm in cryptography?
- To facilitate secure communication
- To encrypt and decrypt data
- To create a unique fixed-length representation of data (Correct answer)
- To generate keys for encryption
Correct answer: To create a unique fixed-length representation of data
A hash algorithm takes an input (or 'message') and returns a fixed-size alphanumeric string, known as a hash value or message digest. This unique representation is used to verify data integrity, as even a small change in the input data will produce a completely different hash value.
Question 5: Which of the following is a primary role of a security architect in the context of Governance, Risk, and Compliance (GRC)?
- Configuring and managing firewall rules and intrusion detection systems.
- Designing and developing security solutions that align with business strategy, policies, and regulatory requirements. (Correct answer)
- Performing daily security operations and incident response.
- Conducting forensic analysis of compromised systems after a security breach.
Correct answer: Designing and developing security solutions that align with business strategy, policies, and regulatory requirements.
A security architect's primary role within GRC is to design security solutions and architectures that are aligned with the organization's vision, mission, strategy, policies, and external factors like laws and regulations. They translate GRC objectives into technical and architectural requirements, ensuring that the security posture supports business goals while managing risk and maintaining compliance.
Question 6: Micro-segmentation in a data center environment is MOST effective at controlling which type of traffic?
- Traffic between branch offices over MPLS
- East-west traffic between workloads within the data center (Correct answer)
- North-south traffic from the internet to servers
- Management traffic to network devices
Correct answer: East-west traffic between workloads within the data center
Micro-segmentation applies granular policies to east-west (lateral) traffic between workloads inside the data center, preventing lateral movement by attackers.
Question 7: What does the principle of "fail-safe defaults" emphasize?
- Systems should default to the most permissive state
- No restrictions should be applied during failure
- Systems should fail in a secure state, restricting access (Correct answer)
- Users should determine default settings
Correct answer: Systems should fail in a secure state, restricting access
The principle of "fail-safe defaults" ensures that when a system component fails or an error occurs, it defaults to a secure, restrictive state rather than an open or permissive one. This prevents unauthorized access or data exposure during system malfunctions, maintaining security.
Question 8: Which cryptographic algorithm is considered asymmetric?
- 3DES (Triple DES)
- DES (Data Encryption Standard)
- AES (Advanced Encryption Standard)
- RSA (Rivest-Shamir-Adleman) (Correct answer)
Correct answer: RSA (Rivest-Shamir-Adleman)
RSA (Rivest-Shamir-Adleman) is a widely used public-key (asymmetric) cryptographic algorithm, meaning it uses a pair of mathematically linked keys: a public key for encryption and a private key for decryption. This allows secure communication without prior sharing of a secret key.
Question 9: Which of the following is the PRIMARY reason for implementing a key rotation policy as part of a cryptographic key management lifecycle?
- To comply with data retention policies.
- To limit the amount of data exposed if a key is compromised. (Correct answer)
- To improve cryptographic performance.
- To simplify the key backup and recovery process.
Correct answer: To limit the amount of data exposed if a key is compromised.
The primary security benefit of key rotation is to limit the 'blast radius' if a key is compromised. By regularly changing keys, the amount of data encrypted with any single key is reduced. Therefore, if an attacker compromises one key, they can only decrypt the data protected by that specific key during its limited crypto-period, not the entire history of the data.
Question 10: Which of the following is the primary goal of security design principles?
- To reduce vulnerabilities and mitigate risks (Correct answer)
- To increase system usability
- To lower operational costs
- To ensure system availability only
Correct answer: To reduce vulnerabilities and mitigate risks
The primary goal of security design principles is to build systems that are inherently resilient against attacks. By incorporating these principles, architects aim to minimize potential weaknesses (vulnerabilities) and reduce the likelihood and impact of security incidents (risks).
Question 11: When designing a federated identity solution using Security Assertion Markup Language (SAML), what is the primary role of the Identity Provider (IdP)?
- To host the application or resource the user wants to access.
- To consume identity assertions and grant or deny access to a resource.
- To provide a centralized repository for storing user passwords and attributes.
- To authenticate the user and issue a security assertion containing identity information. (Correct answer)
Correct answer: To authenticate the user and issue a security assertion containing identity information.
In a SAML federation, the Identity Provider (IdP) is the entity responsible for authenticating the user and, upon successful authentication, creating a security assertion (a SAML token) that contains information about the user's identity and attributes. This assertion is then sent to the Service Provider (SP), which consumes it to make an authorization decision. The SP hosts the resource. While an IdP uses a directory, its primary role in the federation is authentication and assertion issuance.
Question 12: Which security design principle involves dividing a system into smaller parts to reduce overall risk?
- Separation of duties (Correct answer)
- Fail-safe defaults
- Security through obscurity
- Economy of mechanism
Correct answer: Separation of duties
Separation of duties is a security design principle that involves dividing critical tasks among multiple individuals or components to prevent any single person or entity from having complete control. This reduces the risk of fraud, error, or malicious activity by requiring collusion to compromise the system.
Question 13: What is a service provider (SP) in identity federation?
- The organization that owns the user credentials
- A system that relies on identity information from an IdP to grant access (Correct answer)
- A network that connects identity providers
- A protocol used for password encryption
Correct answer: A system that relies on identity information from an IdP to grant access
A Service Provider (SP) is an application or service that relies on an Identity Provider (IdP) to authenticate users. Instead of managing its own user credentials, the SP trusts the IdP to verify the user's identity. Upon successful authentication by the IdP, the SP receives identity information and grants the user access to its resources.
Question 14: What is the primary purpose of identity federation?
- To centralize all user accounts in one database
- To enforce stronger password policies
- To enable seamless access across multiple systems or organizations (Correct answer)
- To encrypt all user credentials
Correct answer: To enable seamless access across multiple systems or organizations
Identity federation allows users to use a single set of login credentials to access resources across different, independent security domains or applications without needing to re-authenticate. This enhances user experience and simplifies identity management, especially in cloud environments or inter-organizational collaborations.
Question 15: A security architect is establishing a proactive threat hunting program. The primary goal is to search for previously unknown or undetected threats that have bypassed existing security controls. Which of the following is the MOST critical architectural prerequisite for enabling effective, hypothesis-driven threat hunting?
- A centralized, long-term repository of searchable endpoint, network, and log data. (Correct answer)
- A complete set of incident response playbooks for all known threat types.
- A real-time dashboard showing alerts from perimeter security devices.
- An automated patching and vulnerability management system.
Correct answer: A centralized, long-term repository of searchable endpoint, network, and log data.
Effective threat hunting is fundamentally dependent on having access to rich, historical data. [21] A centralized and searchable repository (often a data lake or advanced SIEM) containing endpoint process logs, network flow data, DNS queries, and other telemetry is essential. [8] This allows hunters to form a hypothesis (e.g., "an attacker is using DNS for command and control") and then query the historical data to find anomalies and patterns that would not trigger a traditional alert. [21, 23]
Question 16: An organization has discovered that numerous employees are using unauthorized SaaS applications for business purposes, creating a significant 'shadow IT' problem. A security architect needs to recommend a solution that provides visibility into all cloud services in use, enforces data loss prevention (DLP) policies, and offers threat protection for sanctioned and unsanctioned applications. Which of the following is the MOST appropriate architectural component to address these requirements?
- Zero Trust Network Access (ZTNA) Controller
- Web Application Firewall (WAF)
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB) (Correct answer)
Correct answer: Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is specifically designed to address the security gaps created by cloud service usage, including shadow IT. A CASB sits between an organization's on-premises infrastructure and a cloud provider's infrastructure to enforce security policies as users access cloud-based resources. Key functions include discovering all cloud apps in use (sanctioned and unsanctioned), applying DLP policies to data in transit and at rest, and protecting against cloud-based threats.
Question 17: What is the first step in the risk assessment process?
- Monitoring and reviewing risks
- Implementing risk controls
- Identifying assets and their value (Correct answer)
- Performing a gap analysis
Correct answer: Identifying assets and their value
The initial step in any risk assessment process is to identify and categorize the assets that need protection, such as data, systems, and infrastructure. Understanding the value and criticality of these assets helps prioritize security efforts and determine the potential impact of a security incident.
Question 18: What is the principle of "least privilege" in security design?
- Disabling user authentication entirely
- Limiting access rights to the minimum necessary for a role (Correct answer)
- Ensuring all users have administrative access
- Assigning users the highest possible permissions
Correct answer: Limiting access rights to the minimum necessary for a role
The principle of "least privilege" dictates that users, programs, or processes should only be granted the absolute minimum permissions required to perform their legitimate functions. This minimizes the potential damage if an account is compromised, as an attacker would have limited access.
Question 19: As part of the NIST Risk Management Framework (RMF), a security architect is responsible for defining the initial set of security controls for a new information system. This selection is based on the system's security categorization. Which step of the RMF is being performed?
- Select Controls (Correct answer)
- Authorize System
- Assess Controls
- Categorize System
Correct answer: Select Controls
The 'Select Controls' step of the NIST RMF involves choosing an initial baseline of security controls for an information system based on its security categorization (determined in the 'Categorize System' step). The architect then tailors this baseline to align with the organization's specific risk tolerance and operational environment.
Question 20: A security architect is designing a system for a financial institution that must comply with the Sarbanes-Oxley Act (SOX). A primary objective is to align IT processes with business goals and ensure robust internal controls over financial reporting. Which of the following governance frameworks is MOST suitable for achieving this objective?
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- ITIL (Information Technology Infrastructure Library)
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a comprehensive framework for the governance and management of enterprise IT. It is specifically designed to bridge the gap between technical issues, business risks, and control requirements, making it highly suitable for achieving compliance with regulations like SOX that require strong internal controls and alignment between IT and business objectives. While other frameworks are useful, COBIT's core focus is on governance and its link to business goals.
Question 21: Which protocol is commonly used for identity federation?
- SMTP
- DNS
- FTP
- OAuth (Correct answer)
Correct answer: OAuth
OAuth is an open standard for access delegation, commonly used for identity federation. It allows a user to grant a third-party application limited access to their resources on another service without sharing their credentials. This protocol facilitates secure and delegated authorization, making it a key component in modern identity federation architectures.
Question 22: What is the primary purpose of a risk assessment?
- To provide cost estimates for cybersecurity tools
- To identify and evaluate risks to inform decision-making (Correct answer)
- To ensure compliance with industry regulations
- To eliminate all risks
Correct answer: To identify and evaluate risks to inform decision-making
The primary purpose of a risk assessment is to systematically identify potential threats and vulnerabilities, analyze the likelihood and impact of these risks, and then use this information to make informed decisions about risk treatment and mitigation strategies. It helps organizations understand their security posture.
Question 23: The concept of "defense in depth" relies on which of the following?
- A single strong layer of defense
- Multiple redundant layers of security controls (Correct answer)
- A focus on network security only
- Physical security alone
Correct answer: Multiple redundant layers of security controls
"Defense in depth" is a cybersecurity strategy that employs a series of overlapping and redundant security controls to protect information and systems. If one layer of defense fails, subsequent layers are in place to detect and prevent an attack, providing a more robust security posture.
Question 24: A security architect at a multinational corporation is tasked with designing a security architecture that can adapt to a complex and constantly changing regulatory landscape. The architecture must provide a consistent set of reusable security services, such as identity management and network segmentation, across all business units. What is the main benefit of this architectural approach?
- It eliminates the need for all future security testing.
- It completely outsources all security risks to third-party vendors.
- It reduces the initial cost of security implementation to near zero.
- It provides standardization that simplifies demonstrating compliance across multiple regulations. (Correct answer)
Correct answer: It provides standardization that simplifies demonstrating compliance across multiple regulations.
A well-designed security architecture that uses consistent, standardized building blocks and common security services simplifies the process of meeting diverse regulatory obligations. This consistency makes it easier to audit, manage, and demonstrate compliance across the enterprise, even when regulations change or overlap.
Question 25: A security architect must ensure that sensitive network traffic between data centers is protected in transit. Which solution provides both confidentiality and integrity for this traffic?
- IPsec tunnel mode between data center gateways (Correct answer)
- MPLS traffic engineering without encryption
- Using private WAN circuits without additional encryption
- QoS tagging on the WAN links
Correct answer: IPsec tunnel mode between data center gateways
IPsec tunnel mode encrypts the entire original IP packet and provides both confidentiality and integrity verification, protecting data in transit between data centers.
Question 26: A security architect is defining the security verification requirements for a new web application that will handle sensitive medical data (PHI). The application requires the highest level of security assurance. According to the OWASP Application Security Verification Standard (ASVS), which level should be specified?
- Level 3 (Correct answer)
- Level 2
- Level 4
- Level 1
Correct answer: Level 3
The OWASP ASVS defines three security verification levels. Level 3 is the highest and most stringent level, intended for the most critical applications, such as those that handle high-value transactions, sensitive medical data, or any application requiring the highest level of trust. Level 1 is for low-assurance needs, and Level 2 is the standard for applications handling sensitive data. There is no Level 4 in the ASVS standard.
Question 27: Which of the following represents the MOST significant security challenge unique to a serverless (FaaS) architecture compared to a traditional Infrastructure as a Service (IaaS) model where the organization manages the full OS?
- An expanded and more complex attack surface due to event-triggers and function-to-function interactions. (Correct answer)
- The responsibility for physical security of the data center hardware.
- The requirement to configure network-level firewalls and security groups.
- The need for vulnerability scanning of operating systems and kernel patching.
Correct answer: An expanded and more complex attack surface due to event-triggers and function-to-function interactions.
In a serverless architecture, the attack surface shifts from the underlying OS (which is managed by the cloud provider) to the functions themselves and their triggers. Each function can be triggered by numerous event sources (HTTP APIs, storage events, message queues), creating many more entry points for an attacker. Securing the interactions and permissions between dozens or hundreds of ephemeral functions introduces a complexity not present in managing a few monolithic VMs.
Question 28: An architect is applying the defense-in-depth strategy to secure a critical application server. The design includes a perimeter firewall, network segmentation, host-based intrusion prevention system (HIPS), application-level access controls, and data encryption. What is the primary purpose of this layered approach?
- To focus all security resources on preventing initial network penetration.
- To ensure that if one security control fails, others may still be effective in stopping an attack. (Correct answer)
- To eliminate the need for security monitoring and logging.
- To meet the minimum compliance requirements with a single security solution.
Correct answer: To ensure that if one security control fails, others may still be effective in stopping an attack.
The core concept of defense-in-depth is that no single security control is infallible. By implementing multiple, overlapping layers of security, the architecture creates redundancy. If an attacker bypasses one layer (e.g., the perimeter firewall), other layers (like network segmentation or HIPS) are in place to detect or prevent further progress, thus enhancing the overall resilience of the system.
Question 29: Where should an Intrusion Detection System (IDS) sensor be placed to detect attacks targeting a public-facing web server in a DMZ?
- On the internal LAN segment only
- Between the internal network and the DMZ firewall
- Behind the web server on the database segment
- Between the external firewall and the DMZ (Correct answer)
Correct answer: Between the external firewall and the DMZ
Placing an IDS sensor between the external firewall and the DMZ allows it to inspect inbound traffic destined for DMZ services before it reaches those servers.
Question 30: What is Single Sign-On (SSO) in the context of identity federation?
- A way to replicate user accounts
- A system that allows users to authenticate once and access multiple systems (Correct answer)
- A tool for monitoring user activities
- A method to enhance password strength
Correct answer: A system that allows users to authenticate once and access multiple systems
Single Sign-On (SSO) is a core concept in identity federation, enabling users to authenticate their identity once with an identity provider. After this initial authentication, they can then access multiple independent applications or services without needing to re-enter their credentials for each one. This significantly improves user experience and reduces the administrative burden of managing multiple passwords.
Question 31: A security architect is designing a multi-level secure (MLS) database for a government agency. The primary requirement is to prevent an inference attack where a user with a low clearance could deduce the existence of high-level data by observing an error or a null result. Which database security mechanism is specifically designed to mitigate this type of attack?
- Homomorphic Encryption
- Polyinstantiation (Correct answer)
- Database Activity Monitoring (DAM)
- Data Masking
Correct answer: Polyinstantiation
Polyinstantiation is a database security technique used in multi-level secure systems to prevent inference attacks. It allows multiple records with the same primary key to exist in the database, but with different security classifications. A user with a low clearance level would see a different, less-sensitive version of the record instead of an error, preventing them from inferring that a higher-classification record exists.
CISSP-ISSAP: Information Systems Security Architecture Professional
The CISSP-ISSAP is an advanced ISC2 concentration certification validating the expertise of senior security professionals in designing and managing enterprise security architectures across governance, infrastructure, and identity domains. Candidates must hold an active CISSP and demonstrate two years of experience in ISSAP domains.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds