
Information Systems Security Architecture Professional
Domain 2Objective 2
2.2 Verify and Validate Design (e.g., Functional Acceptance Testing, Regression) ISSAP Practice Questions (Page 1)
Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
5concepts
22%of the exam
Questions 1–5
- 1
A financial services firm is validating a new customer-facing web application. The threat model identified a high-impact, high-probability threat of SQL injection in the search feature. The design includes parameterized queries, but the threat model also flagged that the legacy reporting module, which is out of scope for the redesign, still concatenates user input into SQL strings. The security architect must decide how to validate the design before production. Which action best addresses the gap?
Select an answer first - 2
When a proposed security control is not feasible in the current design, a security architect needs to address the identified threat. What is the most appropriate action?
Select an answer first - 3
A security architect is validating a new mobile application. The threat model identified a high-probability threat of data leakage through insecure data storage on the device. The design includes encryption of data at rest. The architect wants to validate that the implementation correctly encrypts data. Which validation method is most appropriate?
Select an answer first - 4
A security architect is validating a new container orchestration platform. The threat model identified a high-impact threat of container escape. The design includes running containers as non-root and using seccomp profiles. The architect must validate the design. The threat model also shows that the container runtime has a known vulnerability that could allow escape. The architect is considering patching the runtime or implementing a compensating control such as a pod security policy. Which approach is most appropriate?
Select an answer first - 5
A security architect asks a colleague who is not involved in the design project to review the architecture for flaws. Which validation method is being applied?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.