- Home
- All questions
- Security architecture
CISSP study material: Security architecture
49 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 3. A shared services division publishes a hardened logging and identity stack that a dozen internal systems will inherit rather than build for themselves. Leadership asks what the authorisation decision covering that published stack must convey to the owners of the inheriting systems.
- 5. A bank is adopting the NIST Cybersecurity Framework 2.0 and the board asks which decisions belong to the Govern function that sits at the centre of the Core. Choose three.
- 10. A software firm's leadership expects the NIST Cybersecurity Framework 2.0 to hand them a configuration standard for their cloud estate. The security lead has to reset that expectation before the programme starts. What does the framework itself provide?
- 22. A retailer is redesigning access after a breach in which an intruder who reached one internal subnet moved freely between servers. The architects want the model described in NIST SP 800-207 zero trust architecture. Which principle should drive the redesign?
- 23. An engineer is building the access flow for a zero trust architecture. A contractor signs in with MFA from a laptop the enterprise has never seen and requests a session to an internal application. Which sequencing matches the SP 800-207 model?
- 24. An architect records a boundary protection control as implemented because a next-generation firewall is deployed with a hardened ruleset. The assessor finds no evidence that the deployed rules behave as designed. Considering the two angles the SP 800-53 Rev. 5 catalogue applies to any control, what is missing?
- 25. A programme manager claims the systems security engineering principles in SP 800-160 Vol. 1 Rev. 1 suit large defence platforms only, so a small sensor gateway that has already been fielded sits outside their scope. How should the security architect answer?
- 26. A governance team wants one control catalogue to serve the whole organisation, so that a single register covers every obligation the board tracks. They ask which concerns beyond classic information security the twenty SP 800-53 Rev. 5 families already govern. Choose two.
- 27. A payments platform encrypts stored card tokens with AES-128. An architect proposes migrating to AES-256 so that each encrypted block becomes larger, cutting the number of blocks and the padding overhead on every record. How should the security engineer assess this proposal?
- 31. A vendor tells a procurement team that its hardware security module is "FIPS validated" because its AES implementation passed algorithm testing. The security engineer reviewing the claim explains that cryptographic module validation under FIPS 140-3 examines considerably more than algorithm correctness. Which areas does that validation cover? Choose two.
- 32. A manufacturer is rebuilding remote access around a zero trust architecture. Engineers argue that company-issued laptops sitting on the plant's internal LAN should reach the production historian directly, since both the hardware and the segment are corporate property. The security architect rejects this. Which statement reflects the model the architect is applying?
- 33. A network architect is numbering an isolated test range that must stay unroutable on the public internet, and wants only address space set aside for private internets. Four candidate blocks appear in the addressing plan. Which blocks are reserved for private internets? Choose three.
- 38. A security engineer is building the ordered policy table an IPsec implementation consults for every packet crossing the boundary, and a reviewer wants the test plan to cover every outcome a policy lookup can produce. Which dispositions can a lookup return? Choose three.
- 43. A contractor is choosing authenticators for a system that must operate at Authentication Assurance Level 3 (AAL3) under NIST SP 800-63B-4. The security architect proposes passkeys synchronised across each staff member's phone and laptop through a cloud account. Why does this proposal fail the AAL3 requirement?
- 52. An architect replaces static group permissions on a research data platform with attribute based access control (ABAC), so that the particulars of each request decide the outcome rather than a fixed grant. Which inputs does the ABAC decision test against the rule set? Choose three.
- 65. An organisation is writing the mitigation section of its incident response plan for workloads hosted by a cloud provider whose platform contains some incidents automatically. Which two requirements should that section state? Choose two.
- 73. A financial services firm runs three delivery groups: one on a waterfall life cycle, one on Scrum, and one on continuous delivery. The CISO wants a single consistent set of secure-development expectations across all three without forcing them onto one common life-cycle model. Which approach fits the Secure Software Development Framework (SSDF) as it is published?
- 193. A vendor claims its product delivers zero trust because it removes the perimeter firewall. Why does NIST SP 800-207 reject definitions framed this way?
- 194. A design grants unauthenticated access to a records service for any host on the corporate LAN, on the grounds that the LAN sits behind the firewall. Which zero trust tenet does this breach?
- 195. A single sign-on deployment issues a token at login that admits the user to every application in the estate for eight hours. Which two zero trust expectations does this arrangement fail? Choose two.
- 196. An access policy is written purely as a static list of groups and applications. Which inputs does SP 800-207 expect a zero trust policy to weigh instead? Choose three.
- 197. In the SP 800-207 conceptual model, which component makes and logs the access decision, and which one carries that decision out?
- 198. A session is approved. Which two things does the policy administrator do next, in the SP 800-207 model? Choose two.
- 199. An architect asks how the policy enforcement point may be realised in practice under SP 800-207. Which description is correct?
- 200. A design places zero trust component communication on the same network segment as application traffic. Which separation does SP 800-207 describe?
- 201. What does the policy engine feed into its trust algorithm before granting, denying or revoking access?
- 202. Which three pieces of information does a continuous diagnostics and mitigation system supply to the policy engine about a requesting asset? Choose three.
- 203. An architect writing a zero trust network plan asks what posture to adopt toward the enterprise's own private network. What does SP 800-207 assume?
- 204. A field engineer connects a corporate laptop to a hotel network. What posture does SP 800-207 tell that remote asset to take?
- 205. A workload is migrated from an on-premises data centre to a cloud instance and loses several of the controls it previously ran under. Which zero trust assumption does this violate?
- 206. A gateway grants access whenever the user presents valid credentials, without examining the device the request came from. Which two zero trust points does this miss? Choose two.
- 207. A retailer proposes applying its full zero trust tenets to anonymous shoppers browsing its public catalogue. What does SP 800-207 say about that scope?
- 208. A zero trust deployment restricts what each subject may open, but every subject can still enumerate the full catalogue of resources. Which aspect of least privilege does SP 800-207 say is missing?
- 209. An executive asks what changed in enterprise computing to prompt zero trust, and what zero trust protects as a result. Which answer matches SP 800-207?
- 210. A team must decide when an established session should be re-evaluated. Which triggers does SP 800-207 name? Choose three.
- 211. A procurement team insists zero trust requires certificate-based authentication specifically. What does SP 800-207 say about technology choices?
- 212. An enterprise allows staff to reach its resources from their own phones. Under the first zero trust tenet, how may those phones be treated?
- 213. A product implements the policy engine and policy administrator as one service. Is that consistent with SP 800-207, and why does the publication still separate them?
- 214. A team is testing whether a managed offering meets the NIST definition of cloud computing. Which three of the five essential characteristics are listed below? Choose three.
- 215. A provider requires customers to email an account manager before additional storage is allocated, with provisioning completed within two working days. Which essential characteristic does the offering fail?
- 216. A customer asks its cloud provider exactly which rack its virtual machines run on and is told only the country and datacentre. Which two facts about resource pooling explain this? Choose two.
- 217. A finance team asks how it can verify what a cloud service actually consumed last month, and how the provider justifies the invoice. Which essential characteristic covers this?
- 218. A customer of a hosted email service asks to patch the operating system underneath it. Under the NIST definition, what may a software as a service consumer actually control?
- 219. A development team deploys its own applications onto a provider's runtime, using languages and libraries the provider supports. Which two things does the NIST definition say the consumer controls in platform as a service? Choose two.
- 220. Which service model, under the NIST definition, lets a consumer run arbitrary software including operating systems and sometimes control select networking components such as a host firewall?
- 221. An auditor argues a cloud cannot be private because the hardware is owned and operated by an outside supplier in the supplier's own datacentre. What does the NIST definition say?
- 222. Several hospital trusts share an infrastructure provisioned for their exclusive use because they face the same regulatory regime. Which NIST deployment model is this, and who may run it?
- 223. An architect looking for privacy controls is told to consult a separate NIST publication from the security control catalogue. What changed in SP 800-53 Rev. 5?
- 224. An engineer is asked which NIST publication addresses building systems that must keep working while under attack, and what discipline it names for that work. Which answer is correct?