
Information Systems Security Architecture Professional
Domain 2Objective 1
2.1 Identify Security Architecture Approach ISSAP Practice Questions (Page 7)
Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
22%of the exam
Questions 31–35
- 31
An architect is documenting the security architecture for a new e-commerce platform. The blueprint must clearly show how the web application firewall (WAF), the API gateway, and the identity provider (IdP) interact to protect the application. Which type of architecture blueprint is most appropriate for this purpose?
Select an answer first - 32
What is the primary purpose of the TOGAF Architecture Development Method (ADM)?
Select an answer first - 33
A government agency is building a new secure data exchange platform. The architect wants to use a proven, standardized set of security patterns and components rather than designing from scratch. The agency requires a template that has been validated for similar high-assurance environments. What should the architect use?
Select an answer first - 34
A large enterprise is updating its threat model for its cloud-based customer relationship management (CRM) system. The security architect wants to incorporate recent threat intelligence indicating that a specific advanced persistent threat (APT) group is targeting similar CRM platforms in the same industry. How should the architect integrate this intelligence into the threat modeling process?
Select an answer first - 35
A logistics company is replacing its monolithic legacy system with a service-oriented architecture (SOA). The security architect must design the security architecture for the new system. The architect is concerned about threats that target the message exchanges between services, such as message alteration and unauthorized replay. Which type of security architecture is most directly relevant to addressing these concerns?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ISSAP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.