Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Architecture Professional

Domain 2Objective 1

2.1 Identify Security Architecture Approach ISSAP Practice Questions (Page 4)

Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
10concepts
22%of the exam

Questions 16–20

  1. 16expert · hard

    A security architect is threat modeling a new payment processing system. The system is a microservices-based application deployed in a public cloud. The architect has identified a threat where an attacker who compromises one microservice could use its service account to access other microservices and escalate privileges. This is a specific example of which STRIDE threat, and what is the most effective architectural mitigation?

    Select an answer first
  2. 17expert · hard

    A large enterprise is using TOGAF to develop its architecture. The security architect is responsible for ensuring that security is integrated into the Architecture Development Method (ADM). The architect has noticed that in previous projects, security was only considered during Phase D (Technology Architecture), leading to costly rework. The architect wants to ensure security is considered throughout the ADM. What is the most effective way to achieve this?

    Select an answer first
  3. 18foundation · easy

    Which artifact in the Service-Oriented Modeling Framework (SOMF) is used to document the security requirements for a service?

    Select an answer first
  4. 19application · medium

    A financial services firm is redesigning its security architecture. The CISO insists that the architecture must be traceable from the board-level business strategy down to the specific security controls and technologies. The architect needs a framework that explicitly maps business drivers to security services and mechanisms. Which framework should the architect use?

    Select an answer first
  5. 20foundation · easy

    Which framework is specifically designed to align security architecture with business requirements by using a layered approach that maps business drivers to security services?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.