All questions

Information Systems Security Architecture Professional (ISSAP) Practice Exam

Browse all practice questions for the Information Systems Security Architecture Professional (ISSAP) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

ISSAP Practice Exam 2026 – The All-in-One Guide to Mastering Information Systems Security Architecture! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which combination best aligns with a secure wireless network architecture?
  • In the context of a security baseline, what is the primary purpose of difference analysis?
  • Which term describes the process of identifying and addressing weaknesses that could lead to a security breach?
  • What is a trust boundary, and why is it critical in ISSAP design?
  • Which term best describes a process of understanding threats, determining risks, and establishing mitigations?
  • Which PKI component is primarily responsible for validating a certificate applicant's identity during enrollment?
  • Which term describes an interface between systems, often between an application and multiple underlying legacy systems?
  • Which statement describes Layered Defense in security architecture?
  • What is Middleware in system architecture?
  • Which are key components of a disaster recovery plan in ISSAP?
  • Certification is defined as?
  • What is the practice of ensuring that no organizational process can be completed by a single person; forces collusion as a means to reduce insider threats?
  • Which term describes a component (service) - based distributed architecture?
  • Which term guards against improper information modification or destruction and includes ensuring information non-repudiation and authenticity?
  • Which device sits at the edge of a network to regulate traffic and enforce rules?
  • What is the fixed-length value produced by a hash function called?
  • Which of the following describes Business Continuity?
  • Which term describes a gateway device at the edge of a network?
  • How do RTO and RPO differ in disaster recovery planning?
  • Which concept provides non-repudiation in communications by binding the sender with the message?
  • What term describes a packaged software unit?
  • What is Static Testing?
  • BCDR is defined as?
  • What is data classification, and how does it influence security controls?
  • What is Baseline?
  • Which term describes a model where processing can be done at many connected locations?
  • The process of converting the message from plaintext to ciphertext.
  • Which concept is about preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information?
  • How does segmentation differ from zoning, and when would you apply each?
  • Which term describes a technique that produces a fixed-size value to verify data integrity?
  • What is the primary purpose of an architecture security board or governance forum?
  • Which term is also known as accreditation?
  • Software-defined Wide Area Network (SD-WAN) extends SDN practices to connect entities how?
  • How should security metrics be defined and applied in evaluating an architecture?
  • How do privacy regulations such as GDPR and CCPA influence security architecture decisions?
  • Which term describes a one-way function producing a fixed-length digest?
  • Who is responsible for protecting an asset that has value, while in one's possession?
  • Which design elements contribute to resilience and availability in ISSAP?
  • Which cryptographic operation works on data arranged in blocks?
  • Which term describes a suitable level of risk commensurate with the potential benefits of the organization's operations as determined by senior management?
  • Describe PKI components and their relevance to secure architectures.
  • Which term denotes an entity that collects or creates PII?
  • What describes the role of physical security within ISSAP and its integration with cyber security?
  • Who qualifies as a stakeholder?
  • Which risk assessment method is designed for probabilistic, quantitative risk analysis?
  • Which term describes a packaged software unit that includes code and dependencies to ensure reliable deployment across environments?
  • Define a security perimeter, its components, and the role it plays in architecture.
  • Which statement best captures the purpose of an architecture governance forum?
  • Which term describes accounts on a system with higher levels of permissions?
  • Which term refers to the determination of the best way to address an identified risk?
  • What does residual risk refer to in security risk management?
  • Which statement best describes threat intelligence in ISSAP decisions?
  • How does cloud security differ across IaaS, PaaS, and SaaS models, and what is the shared responsibility model?
  • Which concept refers to the inability to deny that a message was sent and its integrity remains intact?
  • Which term refers to moral principles that govern behavior?
  • Which technologies apply to data encryption at rest and data encryption in transit, and why both are important?
  • Which term describes an entity that collects or creates PII?
  • Which option correctly defines the term that is a formal review of software to ensure all security controls are built into the software as designed?
  • From a security perspective, what describes secure caching and data storage optimization?
  • Privileged Accounts are accounts on a system with higher levels of permissions.
  • What term best describes the process of how an organization is managed, including decision-making, policies, roles, and procedures?
  • Side Channel Attacks are attacks that rely on what aspect of a cryptographic system?
  • Which term denotes the principle of granting users the minimal permissions necessary to perform their job?
  • Which term is a secure management communications channel?
  • What is the action of changing a message into another format through the use of a code?
  • Which concept is a small representation of a message used to ensure authentication and integrity rather than confidentiality?
  • Which governance mechanism is commonly used to align security requirements with business processes in ISSAP?
  • Which term describes software modules that are linked to one another and operate together?
  • Accepts an input message of any length and generates a fixed-length output via a one-way operation.
  • Systems Authorization is described as?
  • What are the essential components of a security governance program within ISSAP?
  • Describe the general tradeoffs between security, usability, and performance in architectural decisions.
  • Which practice involves only granting a user the minimal permissions necessary to perform their explicit job function?
  • What characterizes a zero-trust security model in an enterprise ISSAP approach?
  • Which term describes safeguards and countermeasures commensurate with the level of risk?
  • Which term is used for a formal statement of ownership of a public encryption key?
  • What term describes the ability to switch cryptographic algorithms and protocols with minimal disruption in enterprise environments?
  • STRIDE is a threat model taxonomy used to identify and mitigate threats early in design.
  • Which of the following is Static Testing?
  • Which elements are essential when designing secure Internet of Things (IoT) and operational technology (OT) environments?
  • In Software-defined Networking, which planes are involved in data handling and management?
  • Which practices are included in managing the secure lifecycle of virtual machines?
  • Which term describes a safeguard or countermeasure used to mitigate risk; it may be technical, managerial or physical?
  • Which concept is the formal process of evaluating and prioritizing security risks by considering both probability and impact?
  • Which statement best captures the difference between SABSA and TOGAF in security architecture?
  • Which term refers to the role of managing data on a day-to-day basis within an organization on behalf of the data owner/controller?
  • Which term describes awareness of the system state and changes in state?
  • Business Impact Analysis (BIA) is defined as?
  • What is a risk register, and how is it used within ISSAP projects?
  • Explain secure software development lifecycle (SSDLC) and its integration into enterprise architecture.
  • What is the purpose of mutual authentication in IoT/OT design?
  • Which description best characterizes the risk assessment methods commonly used in ISSAP?
  • Describe a data-centric security approach and its benefits.
  • In many enterprise architecture frameworks, security is treated as what?
  • What is Centralized Architecture?
  • Which term describes the ability to continue essential operations during a disruption?
  • Proof of Possession is a way to verify ownership of an identity.
  • What is a Pseudorandom Number Generator (PRNG) used for?
  • Threat intelligence primarily informs which security activities?
  • Software-defined Networks (SDNs) focus on segregating which elements?
  • Dynamic Testing is testing of the functionality of software; also known as black box testing.
  • What best defines an Initialization Vector (IV) in cryptography?
  • What is a cryptographic key management lifecycle, and why is it critical?
  • What is ABAC, and when is it preferred over RBAC in ISSAP designs?
  • Provisioning Identities is Setting up identities on a system.
  • Which of the following is an example of a security performance metric?
  • Which of the following is a consideration in privacy-by-design security architecture?
  • Which statement best describes enforcing the principle of least privilege in an enterprise architecture?
  • In threat modeling for cloud migration, which framework is commonly used to categorize threats and map to mitigations?
  • State in a computing context is defined as what?
  • Which activity is described as the attempt to enter a system or network through an unauthorized channel?
  • Which principle best describes balancing security, usability, and performance without compromising essential protections?
  • Which practice contributes to secure Internet of Things and OT environments?
  • How do you assess the security of a supply chain and third-party risk within ISSAP?
  • Which term denotes the possibility of damage or harm and the likelihood that damage or harm will be realized?
  • Which steps are involved in threat modeling for an enterprise cloud migration?
  • Which term describes IT services acquired outside of the traditional IT department?
  • Which statement is NOT a component of a security governance program?
  • Which concept describes the management of Identities throughout the identity management lifecycle?
  • Which activity involves proving that an existing control is the correct control?
  • Which term means actions taken by a vendor to demonstrate or provide due care?
  • Which formal statement asserts ownership of a public encryption key?
  • Which term represents an overarching governance mechanism for security strategy, typically enacted by senior leadership?
  • Which term is the examination of evidence related to criminal activity?
  • Which term describes an agreement between the United States and the European Union related to the transmission of EU citizens' data to the United States?
  • Which term describes cryptography using two keys where one encrypts and the other decrypts?
  • What does Perfect Forward Secrecy (PFS) ensure in cryptography?
  • What best describes SD-WAN in relation to SDN and cloud migration?
  • Which term entails analyzing the data the organization retains, determining its importance and value, and then assigning it to a category?
  • Which term describes the person/role within the organization who usually manages the data on a day-to-day basis on behalf of the data owner/controller?
  • What is the purpose of a Business Impact Analysis?
  • Dynamic Testing is testing of the functionality of software; also known as black box testing.
  • Which term describes guarding against information modification or destruction and includes ensuring non-repudiation and authenticity?
  • Which term means rules enforced by a regulatory body or authority?
  • What is Vulnerability Management?
  • In AAA, what is the primary purpose of accounting?
  • Which term is the process of identifying, evaluating and controlling threats, including the phases of risk context, risk assessment, risk treatment, and risk monitoring?
  • Which statement correctly describes the core access control models RBAC, MAC, DAC, and ABAC?
  • Which term is the ongoing process to monitor and adjust risk responses and controls as threats evolve?
  • In the cryptographic key management lifecycle, which activity typically follows revocation?
  • Virtual Machines is an emulation of a computing system.
  • What is the role of architecture governance in integrating threat models and risk assessments?
  • A statement best characterizes a computer security incident?
  • Explain the role of incident response planning in the ISSAP discipline.
  • Which term refers to documents published and promulgated by senior management describing the organization's strategic goals?
  • Which term captures international data transfer agreements to protect privacy in cross-border data flows?
  • Which term describes IT systems that have been in use for an extended time period?
  • Which term emphasizes the legal duty a provider owes to a customer and the expectation of reasonable care?
  • Describe the concept of security patterns and provide an example relevant to network security design.
  • How does virtualization security influence architecture decisions?
  • What is the role of governance, risk, and compliance in ISSAP?
  • Which concept is defined as ensuring timely and reliable access to and use of information by authorized users?
  • Which statement accurately defines Layered Defense when protecting assets?
  • Which term entails analyzing the data that the organization retains, determining its importance and value, and then assigning it to a category?
  • Trusted Path is a secure management communications channel.
  • Data classification influences which aspects of security implementation?
  • Defense in depth is best described as?
  • Which term encompasses how an organization is managed; usually includes policies, roles, and procedures the organization uses to make decisions?
  • Entitlement is a set of rules defined by the resource owner for managing access to a resource (asset, service, or entity) and for what purpose.
  • Which term describes devices that enforce administrative security policies by filtering traffic based on rules?
  • Which concept denotes preserving authorized restrictions on information access and disclosure, aimed at ensuring information is accessible by authorized users when needed?
  • In ISSAP operations, what is the function of logging, monitoring, and anomaly detection?
  • Which process converts plaintext into ciphertext to protect confidentiality?
  • Which statement best describes data encryption at rest?
  • Which term is defined as preserving authorized restrictions on information access and disclosure, including the protection of personal privacy and proprietary information?
  • Which process helps developers understand security threats, determine risks, and establish mitigations?
  • Which term describes proving the existence of a control?
  • Which statement best describes the role of architecture frameworks in ISSAP?
  • What elements should a key management policy include?
  • What is the purpose of using an artifact traceability matrix in ISSAP?
  • Which statement best differentiates authentication, authorization, and accounting in access management?
  • Which description best captures Side Channel Attacks?
  • Which technologies are commonly used to protect data in transit?
  • What is a security baseline, and how is it used in ongoing architecture assurance?
  • Which term describes a cryptographic operation that operates on a bit or character at a time?
  • Which term describes a model where processing can be done at many connected locations?
  • What is a SOC, and how does it relate to security operations in enterprise architecture?
  • Which term describes a documented, lowest level of security configuration?
  • What is a security control taxonomy, and why is it important for architecture governance?
  • Which elements define secure identity provisioning and lifecycle management in large enterprises?
  • Disaster Recovery refers to
  • A Computer Security Incident is defined as?
  • Explain identity federation and SSO, and their importance to IAM in ISSAP.
  • Which concept refers to adherence to a mandate; both the actions demonstrating adherence and the tools, processes, and documentation used in adherence.
  • Identity and Access Management (IAM) is the management of Identities throughout the identity management lifecycle.
  • Which statement best describes SSDLC's purpose?
  • BCDR stands for which phrase?
  • Which term describes the legal concept concerning the duty owed by a provider to a customer?
  • Which components are typical of a data-centric security program?
  • In network architecture terms, which statement best describes the three concepts DMZ, internal segmentation, and microsegmentation?
  • Which term is an emulation of a computing system?
  • Which term provides authentication of the sender, ensures message integrity, and non-repudiation services?
  • What is CASB, and how does it support cloud security architecture?
  • Which term refers to an entity that processes data provided to them by the data controller?
  • What best describes Hybrid Encryption?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy