
Information Systems Security Architecture Professional
Domain 2Objective 2
2.2 Verify and Validate Design (e.g., Functional Acceptance Testing, Regression) ISSAP Practice Questions (Page 2)
Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
5concepts
22%of the exam
Questions 6–10
- 6
A security architect is validating a new identity management system. The threat model identified a gap: the design does not include a mechanism for revoking access for terminated employees in a timely manner. The architect is considering two mitigations: integrating with the HR system for automated deprovisioning or implementing a manual review process. The organization has a strict compliance requirement that access be revoked within 24 hours of termination. The HR integration is complex and may take months to implement. What should the architect do?
Select an answer first - 7
A security architect is validating a new API gateway. The threat model identified a risk of broken object level authorization (BOLA) in the API endpoints. The design includes authorization checks in the business logic. The architect wants to validate that the implementation correctly enforces authorization. Which code review methodology is most effective?
Select an answer first - 8
During design validation, a security architect compares the proposed architecture against the security requirements. What is the primary purpose of this comparison?
Select an answer first - 9
A security architect is reviewing a threat model to determine which attack paths are most likely to be exploited. Which output of threat modeling is most directly used for this analysis?
Select an answer first - 10
During design validation, a security architect reviews a threat model and wants to prioritize threats based on the likelihood of exploitation and the potential damage to the organization. Which two attributes of each threat should the architect examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.