
Information Systems Security Architecture Professional
Domain 2Objective 1
2.1 Identify Security Architecture Approach ISSAP Practice Questions (Page 5)
Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
22%of the exam
Questions 21–25
- 21
When determining the scope of a security architecture, which factor most directly influences the architectural decisions?
Select an answer first - 22
An architect is designing the security architecture for a new SOA-based system using the Service-Oriented Modeling Framework (SOMF). The system will expose several services, including a payment service and a user profile service. The architect needs to model the security requirements for these services, including the policies for authentication and authorization. According to SOMF, where should these security requirements be modeled?
Select an answer first - 23
Which CVSS metric describes the conditions required to exploit a vulnerability?
Select an answer first - 24
What is the primary purpose of integrating threat intelligence into security architecture modeling?
Select an answer first - 25
A security architect is prioritizing vulnerabilities for a critical application. The team has identified a remote code execution vulnerability in a web server component. The vulnerability is rated with a CVSS v3.1 base score of 9.8. The application is internet-facing, but the vulnerable component is only accessible from a limited internal network segment. What is the most appropriate initial action for the architect?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.