All questions

Information Systems Security Architecture Professional (ISSAP) Practice Exam

Browse all practice questions for the Information Systems Security Architecture Professional (ISSAP) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Information Systems Security Architecture Professional (ISSAP) Practice Exam 2026 - Free ISSAP Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is Static Testing?
  • Which term provides authentication of the sender, ensures message integrity, and non-repudiation services?
  • Which of the following describes Business Continuity?
  • Which term describes safeguards and countermeasures commensurate with the level of risk?
  • Who is responsible for protecting an asset that has value, while in one's possession?
  • Which design elements contribute to resilience and availability in ISSAP?
  • Which statement accurately defines Layered Defense when protecting assets?
  • Identity and Access Management (IAM) is the management of Identities throughout the identity management lifecycle.
  • Which term describes proving the existence of a control?
  • Which concept is a small representation of a message used to ensure authentication and integrity rather than confidentiality?
  • BCDR stands for which phrase?
  • Which practice involves only granting a user the minimal permissions necessary to perform their explicit job function?
  • Provisioning Identities is Setting up identities on a system.
  • Which term describes accounts on a system with higher levels of permissions?
  • What is the purpose of using an artifact traceability matrix in ISSAP?
  • What is Centralized Architecture?
  • Which term refers to an entity that processes data provided to them by the data controller?
  • What is the purpose of mutual authentication in IoT/OT design?
  • Which statement is NOT a component of a security governance program?
  • In threat modeling for cloud migration, which framework is commonly used to categorize threats and map to mitigations?
  • What best defines an Initialization Vector (IV) in cryptography?
  • Which practices are included in managing the secure lifecycle of virtual machines?
  • Which concept refers to the inability to deny that a message was sent and its integrity remains intact?
  • Which term describes an agreement between the United States and the European Union related to the transmission of EU citizens' data to the United States?
  • Which term is defined as preserving authorized restrictions on information access and disclosure, including the protection of personal privacy and proprietary information?
  • Which concept provides non-repudiation in communications by binding the sender with the message?
  • Which statement best describes SSDLC's purpose?
  • What does Perfect Forward Secrecy (PFS) ensure in cryptography?
  • Which term describes a documented, lowest level of security configuration?
  • Which steps are involved in threat modeling for an enterprise cloud migration?
  • Which concept is about preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information?
  • Describe a data-centric security approach and its benefits.
  • Proof of Possession is a way to verify ownership of an identity.
  • Entitlement is a set of rules defined by the resource owner for managing access to a resource (asset, service, or entity) and for what purpose.
  • Which term describes an interface between systems, often between an application and multiple underlying legacy systems?
  • Which technologies apply to data encryption at rest and data encryption in transit, and why both are important?
  • What is Baseline?
  • Data classification influences which aspects of security implementation?
  • Which statement best captures the difference between SABSA and TOGAF in security architecture?
  • Explain the role of incident response planning in the ISSAP discipline.
  • Which concept is the formal process of evaluating and prioritizing security risks by considering both probability and impact?
  • How do privacy regulations such as GDPR and CCPA influence security architecture decisions?
  • Which term describes IT systems that have been in use for an extended time period?
  • Systems Authorization is described as?
  • Which description best captures Side Channel Attacks?
  • Which device sits at the edge of a network to regulate traffic and enforce rules?
  • Which term refers to the role of managing data on a day-to-day basis within an organization on behalf of the data owner/controller?
  • Explain identity federation and SSO, and their importance to IAM in ISSAP.
  • Which concept refers to adherence to a mandate; both the actions demonstrating adherence and the tools, processes, and documentation used in adherence.
  • How do you assess the security of a supply chain and third-party risk within ISSAP?
  • Which term refers to moral principles that govern behavior?
  • What is Middleware in system architecture?
  • Which term best describes a process of understanding threats, determining risks, and establishing mitigations?
  • Which term describes awareness of the system state and changes in state?
  • Which description best characterizes the risk assessment methods commonly used in ISSAP?
  • Which term represents an overarching governance mechanism for security strategy, typically enacted by senior leadership?
  • Software-defined Networks (SDNs) focus on segregating which elements?
  • What is the practice of ensuring that no organizational process can be completed by a single person; forces collusion as a means to reduce insider threats?
  • Which term is the examination of evidence related to criminal activity?
  • What is a risk register, and how is it used within ISSAP projects?
  • Which term describes cryptography using two keys where one encrypts and the other decrypts?
  • Explain secure software development lifecycle (SSDLC) and its integration into enterprise architecture.
  • Which term is the ongoing process to monitor and adjust risk responses and controls as threats evolve?
  • Accepts an input message of any length and generates a fixed-length output via a one-way operation.
  • Which term entails analyzing the data the organization retains, determining its importance and value, and then assigning it to a category?
  • In many enterprise architecture frameworks, security is treated as what?
  • Which term means actions taken by a vendor to demonstrate or provide due care?
  • Which term describes a one-way function producing a fixed-length digest?
  • What is CASB, and how does it support cloud security architecture?
  • Which term denotes the principle of granting users the minimal permissions necessary to perform their job?
  • Which statement best captures the purpose of an architecture governance forum?
  • Software-defined Wide Area Network (SD-WAN) extends SDN practices to connect entities how?
  • What term describes a packaged software unit?
  • Which components are typical of a data-centric security program?
  • How does segmentation differ from zoning, and when would you apply each?
  • Which term entails analyzing the data that the organization retains, determining its importance and value, and then assigning it to a category?
  • Which term describes a model where processing can be done at many connected locations?
  • What characterizes a zero-trust security model in an enterprise ISSAP approach?
  • Which governance mechanism is commonly used to align security requirements with business processes in ISSAP?
  • Define a security perimeter, its components, and the role it plays in architecture.
  • A Computer Security Incident is defined as?
  • Which statement best differentiates authentication, authorization, and accounting in access management?
  • What term describes the ability to switch cryptographic algorithms and protocols with minimal disruption in enterprise environments?
  • Describe PKI components and their relevance to secure architectures.
  • How does virtualization security influence architecture decisions?
  • Which term denotes the possibility of damage or harm and the likelihood that damage or harm will be realized?
  • Disaster Recovery refers to
  • Which term denotes an entity that collects or creates PII?
  • What is the fixed-length value produced by a hash function called?
  • How does cloud security differ across IaaS, PaaS, and SaaS models, and what is the shared responsibility model?
  • Virtual Machines is an emulation of a computing system.
  • Which term describes IT services acquired outside of the traditional IT department?
  • Which term encompasses how an organization is managed; usually includes policies, roles, and procedures the organization uses to make decisions?
  • What does residual risk refer to in security risk management?
  • Which term describes a safeguard or countermeasure used to mitigate risk; it may be technical, managerial or physical?
  • Certification is defined as?
  • Which term emphasizes the legal duty a provider owes to a customer and the expectation of reasonable care?
  • Describe the general tradeoffs between security, usability, and performance in architectural decisions.
  • Which term describes the person/role within the organization who usually manages the data on a day-to-day basis on behalf of the data owner/controller?
  • What is a Pseudorandom Number Generator (PRNG) used for?
  • Which elements are essential when designing secure Internet of Things (IoT) and operational technology (OT) environments?
  • What is ABAC, and when is it preferred over RBAC in ISSAP designs?
  • Which concept describes the management of Identities throughout the identity management lifecycle?
  • Which term refers to documents published and promulgated by senior management describing the organization's strategic goals?
  • What best describes SD-WAN in relation to SDN and cloud migration?
  • What is Vulnerability Management?
  • Which term is a secure management communications channel?
  • Describe the concept of security patterns and provide an example relevant to network security design.
  • Which statement best describes enforcing the principle of least privilege in an enterprise architecture?
  • Which statement best describes threat intelligence in ISSAP decisions?
  • How do RTO and RPO differ in disaster recovery planning?
  • From a security perspective, what describes secure caching and data storage optimization?
  • Which term describes the legal concept concerning the duty owed by a provider to a customer?
  • Which elements define secure identity provisioning and lifecycle management in large enterprises?
  • Which concept denotes preserving authorized restrictions on information access and disclosure, aimed at ensuring information is accessible by authorized users when needed?
  • What is a cryptographic key management lifecycle, and why is it critical?
  • State in a computing context is defined as what?
  • Threat intelligence primarily informs which security activities?
  • Which activity involves proving that an existing control is the correct control?
  • Which term describes devices that enforce administrative security policies by filtering traffic based on rules?
  • Which of the following is Static Testing?
  • Which activity is described as the attempt to enter a system or network through an unauthorized channel?
  • In the context of a security baseline, what is the primary purpose of difference analysis?
  • What is the purpose of a Business Impact Analysis?
  • In Software-defined Networking, which planes are involved in data handling and management?
  • Which term is also known as accreditation?
  • What is the action of changing a message into another format through the use of a code?
  • Which term guards against improper information modification or destruction and includes ensuring information non-repudiation and authenticity?
  • Which option correctly defines the term that is a formal review of software to ensure all security controls are built into the software as designed?
  • Which term describes the ability to continue essential operations during a disruption?
  • Which concept is defined as ensuring timely and reliable access to and use of information by authorized users?
  • What is the role of architecture governance in integrating threat models and risk assessments?
  • Which practice contributes to secure Internet of Things and OT environments?
  • Which of the following is an example of a security performance metric?
  • Which risk assessment method is designed for probabilistic, quantitative risk analysis?
  • What term best describes the process of how an organization is managed, including decision-making, policies, roles, and procedures?
  • Which term means rules enforced by a regulatory body or authority?
  • Which statement describes Layered Defense in security architecture?
  • The process of converting the message from plaintext to ciphertext.
  • Which technologies are commonly used to protect data in transit?
  • Which are key components of a disaster recovery plan in ISSAP?
  • Which formal statement asserts ownership of a public encryption key?
  • Which cryptographic operation works on data arranged in blocks?
  • Which term describes a technique that produces a fixed-size value to verify data integrity?
  • Privileged Accounts are accounts on a system with higher levels of permissions.
  • Which PKI component is primarily responsible for validating a certificate applicant's identity during enrollment?
  • STRIDE is a threat model taxonomy used to identify and mitigate threats early in design.
  • Dynamic Testing is testing of the functionality of software; also known as black box testing.
  • What best describes Hybrid Encryption?
  • In ISSAP operations, what is the function of logging, monitoring, and anomaly detection?
  • What is data classification, and how does it influence security controls?
  • Which term describes the process of identifying and addressing weaknesses that could lead to a security breach?
  • What is a security control taxonomy, and why is it important for architecture governance?
  • Which statement best describes the role of architecture frameworks in ISSAP?
  • Which term describes a cryptographic operation that operates on a bit or character at a time?
  • In network architecture terms, which statement best describes the three concepts DMZ, internal segmentation, and microsegmentation?
  • What is a security baseline, and how is it used in ongoing architecture assurance?
  • What is a SOC, and how does it relate to security operations in enterprise architecture?
  • What is the role of governance, risk, and compliance in ISSAP?
  • Which term describes a model where processing can be done at many connected locations?
  • Dynamic Testing is testing of the functionality of software; also known as black box testing.
  • Which term describes a gateway device at the edge of a network?
  • Which term describes guarding against information modification or destruction and includes ensuring non-repudiation and authenticity?
  • How should security metrics be defined and applied in evaluating an architecture?
  • Side Channel Attacks are attacks that rely on what aspect of a cryptographic system?
  • Which process helps developers understand security threats, determine risks, and establish mitigations?
  • Which term describes a component (service) - based distributed architecture?
  • Who qualifies as a stakeholder?
  • What is the primary purpose of an architecture security board or governance forum?
  • Which combination best aligns with a secure wireless network architecture?
  • What elements should a key management policy include?
  • Which term describes an entity that collects or creates PII?
  • Which term describes a suitable level of risk commensurate with the potential benefits of the organization's operations as determined by senior management?
  • BCDR is defined as?
  • Business Impact Analysis (BIA) is defined as?
  • Which term describes a packaged software unit that includes code and dependencies to ensure reliable deployment across environments?
  • Defense in depth is best described as?
  • Which statement correctly describes the core access control models RBAC, MAC, DAC, and ABAC?
  • Which statement best describes data encryption at rest?
  • Which term refers to the determination of the best way to address an identified risk?
  • Trusted Path is a secure management communications channel.
  • What are the essential components of a security governance program within ISSAP?
  • A statement best characterizes a computer security incident?
  • In AAA, what is the primary purpose of accounting?
  • Which principle best describes balancing security, usability, and performance without compromising essential protections?
  • Which term describes software modules that are linked to one another and operate together?
  • What describes the role of physical security within ISSAP and its integration with cyber security?
  • What is a trust boundary, and why is it critical in ISSAP design?
  • Which term captures international data transfer agreements to protect privacy in cross-border data flows?
  • In the cryptographic key management lifecycle, which activity typically follows revocation?
  • Which process converts plaintext into ciphertext to protect confidentiality?
  • Which of the following is a consideration in privacy-by-design security architecture?
  • Which term is the process of identifying, evaluating and controlling threats, including the phases of risk context, risk assessment, risk treatment, and risk monitoring?
  • Which term is an emulation of a computing system?
  • Which term is used for a formal statement of ownership of a public encryption key?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy