
Information Systems Security Architecture Professional
Domain 3Objective 2
3.2 Architect Infrastructure and System Security ISSAP Practice Questions (Page 8)
Part of the Infrastructure and System Security Architecture domain, which accounts for 32% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–38 in this domain), expect 7–13 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
14concepts
32%of the exam
Questions 36–40
- 36
Which data repository security technique replaces sensitive data with realistic but fictitious values, allowing the data to be used for testing or development without exposing the original values?
Select an answer first - 37
Which security control is most appropriate for protecting a web client application from cross-site scripting (XSS) attacks?
Select an answer first - 38
Which storage security control is most effective at protecting data at rest on removable media that may be lost or stolen?
Select an answer first - 39
An organization is deploying a new web application that will be accessed by external users. The application is hosted on a server behind a reverse proxy. The security architect needs to protect the application from common web attacks such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the proxy layer?
Select an answer first - 40
What is the primary goal of data loss prevention (DLP) controls?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.