
Information Systems Security Architecture Professional
Domain 2Objective 1
2.1 Identify Security Architecture Approach ISSAP Practice Questions (Page 2)
Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
22%of the exam
Questions 6–10
- 6
A security architect is prioritizing vulnerabilities in a hybrid environment. The team has identified a critical vulnerability (CVSS 9.0) in a customer-facing web application. The same vulnerability also exists in an internal HR application, but the HR application is not internet-facing and has compensating controls in place. Threat intelligence indicates active exploitation of this vulnerability in the wild. What is the most appropriate prioritization strategy?
Select an answer first - 7
Which security architecture type focuses on protecting the flow of data across network segments and enforcing access control at the network layer?
Select an answer first - 8
An architect is creating a security blueprint for a new system. The blueprint must communicate the security architecture to both technical teams and business stakeholders. The architect wants to show the high-level security domains (e.g., identity, data, network) and how they relate to business processes. Which type of blueprint is most suitable for this audience?
Select an answer first - 9
A multinational retail company is adopting TOGAF to standardize its architecture practice. The security architect must ensure that security requirements are embedded in every phase of the architecture development cycle, from the initial business vision through the final implementation and migration plan. Which TOGAF component should the architect leverage to achieve this integration?
Select an answer first - 10
A security architect is defining the scope of a security architecture for a multinational enterprise that operates both on-premises data centers and multiple public cloud regions. Which statement best describes the scope of the security architecture in this context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.