ISC2 CISSP Secure Design Principles Models And System Requirements Practice Test

 

3 Security Architecture and Engineering • 26 original questions

This CISSP practice test focuses on secure design principles models and system requirements through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

After a business change, Margie Travel discovers that Shared responsibility is not handled consistently for the clinical records environment. The chief information security officer needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The architecture contains 28 separately managed trust zones or platform components.

  1. Identify the cryptanalytic or credential attack class and mitigate the exploited weakness rather than merely increasing unrelated perimeter controls.
  2. Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response.
  3. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  4. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.

Correct answer: C

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Shared responsibility while keeping the control sustainable for normal operations.

Option review:

A: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Shared responsibility in this scenario.

B: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Shared responsibility in this scenario.

C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Shared responsibility while keeping the control sustainable for normal operations.

D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Shared responsibility in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 2

Wide World Importers is preparing a security decision for the remote access service. The decision involves Secure access service edge (SASE). The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The architecture contains 45 separately managed trust zones or platform components.

  1. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  2. Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure.
  3. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure access service edge (SASE) while ensuring the decision can be repeated consistently across business units.

Option review:

A: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Secure access service edge (SASE) in this scenario.

B: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Secure access service edge (SASE) in this scenario.

C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure access service edge (SASE) while ensuring the decision can be repeated consistently across business units.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Secure access service edge (SASE) in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 3

During a risk workshop for the customer identity platform, the team identifies Bell-LaPadula confidentiality model as the deciding issue. The security assurance manager is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The architecture contains 62 separately managed trust zones or platform components.

  1. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  2. Use a confidentiality model that prevents read-up and write-down across security labels.
  3. Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: B

Why: Bell-LaPadula is designed to protect confidentiality through mandatory information-flow rules. It directly addresses Bell-LaPadula confidentiality model while preserving clear accountability and audit evidence.

Option review:

A: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Bell-LaPadula confidentiality model in this scenario.

B: Bell-LaPadula is designed to protect confidentiality through mandatory information-flow rules. It directly addresses Bell-LaPadula confidentiality model while preserving clear accountability and audit evidence.

C: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Bell-LaPadula confidentiality model in this scenario.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Bell-LaPadula confidentiality model in this scenario.

Learning point: Use a confidentiality model that prevents read-up and write-down across security labels. Bell-LaPadula is designed to protect confidentiality through mandatory information-flow rules.

Question 4

A control owner at Litware Services proposes a quick technical fix for Biba integrity model in the data analytics lake. The enterprise security engineer must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The architecture contains 79 separately managed trust zones or platform components.

  1. Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response.
  2. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  3. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  4. Use an integrity model that prevents subjects from contaminating higher-integrity data.

Correct answer: D

Why: Biba focuses on preserving integrity rather than confidentiality. It directly addresses Biba integrity model while protecting sensitive data throughout the change.

Option review:

A: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Biba integrity model in this scenario.

B: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Biba integrity model in this scenario.

C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Biba integrity model in this scenario.

D: Biba focuses on preserving integrity rather than confidentiality. It directly addresses Biba integrity model while protecting sensitive data throughout the change.

Learning point: Use an integrity model that prevents subjects from contaminating higher-integrity data. Biba focuses on preserving integrity rather than confidentiality.

Question 5

Humongous Insurance is standardizing security across several business units. The branch-office network raises a question about Star-property security model concepts. The chief information security officer needs to address the control objective while preserving availability of the critical business service. Which action provides the BEST governance and security outcome? The architecture contains 5 separately managed trust zones or platform components.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.
  3. Apply the formal model whose star-property and information-flow rules match the required security objective.
  4. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.

Correct answer: C

Why: Formal models should be selected by the property and information-flow rule they are intended to enforce. It directly addresses Star-property security model concepts while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Star-property security model concepts in this scenario.

B: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Star-property security model concepts in this scenario.

C: Formal models should be selected by the property and information-flow rule they are intended to enforce. It directly addresses Star-property security model concepts while preserving availability of the critical business service.

D: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Star-property security model concepts in this scenario.

Learning point: Apply the formal model whose star-property and information-flow rules match the required security objective. Formal models should be selected by the property and information-flow rule they are intended to enforce.

Question 6

During a secure software initiative, Woodgrove Bank asks the risk manager to address System security requirements and control selection for its industrial control network. The requirement is to address the control objective without replacing governance with a technology-only shortcut. What should the organization do FIRST? The architecture contains 22 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Assess the architecture-specific attack surface and shared-responsibility boundary, then apply controls tailored to the platform and its failure modes.
  3. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: C

Why: Control selection is defensible when it traces to requirements and risk rather than vendor preference. It directly addresses System security requirements and control selection without replacing governance with a technology-only shortcut.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address System security requirements and control selection in this scenario.

B: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address System security requirements and control selection in this scenario.

C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. It directly addresses System security requirements and control selection without replacing governance with a technology-only shortcut.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address System security requirements and control selection in this scenario.

Learning point: Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products. Control selection is defensible when it traces to requirements and risk rather than vendor preference.

Question 7

Relecloud Systems is revising controls for its research data repository. A review highlights Memory protection. The security assurance manager must address the control objective while keeping the process defensible to auditors and business owners. Which action is the BEST next step? The architecture contains 39 separately managed trust zones or platform components.

  1. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.
  2. Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Choose modern cryptography and key-management practices that match the confidentiality, integrity, authentication, and lifecycle requirements, and protect keys as carefully as the data.

Correct answer: A

Why: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Memory protection while keeping the process defensible to auditors and business owners.

Option review:

A: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Memory protection while keeping the process defensible to auditors and business owners.

B: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Memory protection in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Memory protection in this scenario.

D: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Memory protection in this scenario.

Learning point: Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement. Built-in system capabilities can provide stronger trust anchors when they directly support the required security property.

Question 8

An auditor asks Contoso Financial to demonstrate how it handles Trusted Platform Module (TPM) in the payment processing service. The enterprise security engineer must address the control objective while minimizing irreversible action until facts and authority are established. Which response is MOST appropriate? The architecture contains 56 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.
  3. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Trusted Platform Module (TPM) while minimizing irreversible action until facts and authority are established.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. That action can be useful in a different security decision, but it does not most directly address Trusted Platform Module (TPM) in this scenario.

B: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Trusted Platform Module (TPM) while minimizing irreversible action until facts and authority are established.

C: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Trusted Platform Module (TPM) in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Trusted Platform Module (TPM) in this scenario.

Learning point: Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement. Built-in system capabilities can provide stronger trust anchors when they directly support the required security property.

Question 9

After a business change, Lucerne Publishing discovers that Encryption and decryption capabilities is not handled consistently for the software delivery pipeline. The chief information security officer needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The architecture contains 73 separately managed trust zones or platform components.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.
  3. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  4. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.

Correct answer: B

Why: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Encryption and decryption capabilities while preserving evidence needed for later review.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Encryption and decryption capabilities in this scenario.

B: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. It directly addresses Encryption and decryption capabilities while preserving evidence needed for later review.

C: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Encryption and decryption capabilities in this scenario.

D: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Encryption and decryption capabilities in this scenario.

Learning point: Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement. Built-in system capabilities can provide stronger trust anchors when they directly support the required security property.

Question 10

Lamna Healthcare is preparing a security decision for the AI-assisted customer service platform. The decision involves Threat modeling. The risk manager must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The architecture contains 90 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Choose modern cryptography and key-management practices that match the confidentiality, integrity, authentication, and lifecycle requirements, and protect keys as carefully as the data.
  3. Identify the cryptanalytic or credential attack class and mitigate the exploited weakness rather than merely increasing unrelated perimeter controls.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Threat modeling without granting broader privilege than the business need requires.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Threat modeling without granting broader privilege than the business need requires.

B: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

C: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 11

During a risk workshop for the global collaboration platform, the team identifies Least privilege as the deciding issue. The security assurance manager is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The architecture contains 16 separately managed trust zones or platform components.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  3. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  4. Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure.

Correct answer: C

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Least privilege without creating a new single point of failure.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

B: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Least privilege without creating a new single point of failure.

D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 12

A control owner at Consolidated Messenger proposes a quick technical fix for Defense in depth in the e-commerce application. The enterprise security engineer must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The architecture contains 33 separately managed trust zones or platform components.

  1. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.
  2. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  3. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  4. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.

Correct answer: D

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Defense in depth while ensuring that emergency access cannot become permanent access.

Option review:

A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

D: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Defense in depth while ensuring that emergency access cannot become permanent access.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 13

Proseware Labs is standardizing security across several business units. The clinical records environment raises a question about Secure defaults. The chief information security officer needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The architecture contains 50 separately managed trust zones or platform components.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  3. Identify the cryptanalytic or credential attack class and mitigate the exploited weakness rather than merely increasing unrelated perimeter controls.
  4. Choose modern cryptography and key-management practices that match the confidentiality, integrity, authentication, and lifecycle requirements, and protect keys as carefully as the data.

Correct answer: B

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure defaults while allowing independent verification of the control outcome.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure defaults while allowing independent verification of the control outcome.

C: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

D: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 14

During a third-party onboarding review, Southridge Media asks the risk manager to address Fail securely for its remote access service. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The architecture contains 67 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Assess the architecture-specific attack surface and shared-responsibility boundary, then apply controls tailored to the platform and its failure modes.
  3. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.
  4. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Fail securely while accounting for third-party and lifecycle dependencies.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Fail securely while accounting for third-party and lifecycle dependencies.

B: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

C: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 15

Adventure Works is revising controls for its customer identity platform. A review highlights Segregation of Duties (SoD). The security assurance manager must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The architecture contains 84 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  3. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  4. Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Segregation of Duties (SoD) while maintaining the organization’s stated risk appetite.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Segregation of Duties (SoD) while maintaining the organization’s stated risk appetite.

B: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

D: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 16

An auditor asks VanArsdel Energy to demonstrate how it handles Keep it simple and small in the data analytics lake. The enterprise security engineer must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The architecture contains 10 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Assess the architecture-specific attack surface and shared-responsibility boundary, then apply controls tailored to the platform and its failure modes.
  3. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Keep it simple and small while meeting the business objective with the least unnecessary operational complexity.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Keep it simple and small while meeting the business objective with the least unnecessary operational complexity.

B: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 17

After a business change, Northwind Health discovers that Zero trust or trust but verify is not handled consistently for the branch-office network. The chief information security officer needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The architecture contains 27 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  3. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  4. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Zero trust or trust but verify while keeping the control sustainable for normal operations.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Zero trust or trust but verify while keeping the control sustainable for normal operations.

B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

C: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

D: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 18

Coho Insurance is preparing a security decision for the industrial control network. The decision involves Threat modeling. The risk manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The architecture contains 44 separately managed trust zones or platform components.

  1. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  2. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.

Correct answer: D

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Threat modeling while ensuring the decision can be repeated consistently across business units.

Option review:

A: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

B: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Threat modeling in this scenario.

D: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Threat modeling while ensuring the decision can be repeated consistently across business units.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 19

During a risk workshop for the research data repository, the team identifies Least privilege as the deciding issue. The security assurance manager is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The architecture contains 61 separately managed trust zones or platform components.

  1. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  2. Assess the architecture-specific attack surface and shared-responsibility boundary, then apply controls tailored to the platform and its failure modes.
  3. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  4. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.

Correct answer: C

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Least privilege while preserving clear accountability and audit evidence.

Option review:

A: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

B: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Least privilege while preserving clear accountability and audit evidence.

D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Least privilege in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 20

A control owner at Blue Yonder Airlines proposes a quick technical fix for Defense in depth in the payment processing service. The enterprise security engineer must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The architecture contains 78 separately managed trust zones or platform components.

  1. Choose modern cryptography and key-management practices that match the confidentiality, integrity, authentication, and lifecycle requirements, and protect keys as carefully as the data.
  2. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  3. Identify the cryptanalytic or credential attack class and mitigate the exploited weakness rather than merely increasing unrelated perimeter controls.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Defense in depth while protecting sensitive data throughout the change.

Option review:

A: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Defense in depth while protecting sensitive data throughout the change.

C: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Defense in depth in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 21

City Power is standardizing security across several business units. The software delivery pipeline raises a question about Secure defaults. The chief information security officer needs to address the control objective while preserving availability of the critical business service. Which action provides the BEST governance and security outcome? The architecture contains 4 separately managed trust zones or platform components.

  1. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  2. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  3. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  4. Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure.

Correct answer: B

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure defaults while preserving availability of the critical business service.

Option review:

A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Secure defaults while preserving availability of the critical business service.

C: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

D: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Secure defaults in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 22

During a acquisition integration, Tailspin Logistics asks the risk manager to address Fail securely for its AI-assisted customer service platform. The requirement is to address the control objective without replacing governance with a technology-only shortcut. What should the organization do FIRST? The architecture contains 21 separately managed trust zones or platform components.

  1. Integrate security requirements, verification, change control, maintenance, and secure disposal throughout the information-system lifecycle.
  2. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  3. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  4. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.

Correct answer: C

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Fail securely without replacing governance with a technology-only shortcut.

Option review:

A: Security decisions must be maintained and revalidated as the system moves from requirements through retirement. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

C: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Fail securely without replacing governance with a technology-only shortcut.

D: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Fail securely in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 23

Alpine Sports is revising controls for its global collaboration platform. A review highlights Segregation of Duties (SoD). The security assurance manager must address the control objective while keeping the process defensible to auditors and business owners. Which action is the BEST next step? The architecture contains 38 separately managed trust zones or platform components.

  1. Deploy a new security product immediately before confirming scope, ownership, or the required security outcome.
  2. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  3. Assess the architecture-specific attack surface and shared-responsibility boundary, then apply controls tailored to the platform and its failure modes.
  4. Select and place site-security controls from a threat and criticality assessment, considering layered deterrence, detection, delay, and response.

Correct answer: B

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Segregation of Duties (SoD) while keeping the process defensible to auditors and business owners.

Option review:

A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Segregation of Duties (SoD) while keeping the process defensible to auditors and business owners.

C: Different platforms create distinct vulnerabilities; effective mitigation depends on architecture context rather than one universal hardening checklist. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

D: Facility security is most effective when physical controls are designed as a coordinated system around threats and business criticality. That action can be useful in a different security decision, but it does not most directly address Segregation of Duties (SoD) in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 24

An auditor asks Fabrikam Manufacturing to demonstrate how it handles Keep it simple and small in the e-commerce application. The enterprise security engineer must address the control objective while minimizing irreversible action until facts and authority are established. Which response is MOST appropriate? The architecture contains 55 separately managed trust zones or platform components.

  1. Derive controls from explicit system security requirements, threat assumptions, and assurance needs before choosing products.
  2. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  3. Choose modern cryptography and key-management practices that match the confidentiality, integrity, authentication, and lifecycle requirements, and protect keys as carefully as the data.
  4. Grant a small operations group broad administrator access so they can work around the issue whenever it appears.

Correct answer: B

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Keep it simple and small while minimizing irreversible action until facts and authority are established.

Option review:

A: Control selection is defensible when it traces to requirements and risk rather than vendor preference. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

B: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Keep it simple and small while minimizing irreversible action until facts and authority are established.

C: Cryptographic strength depends on algorithms, key management, certificate trust, implementation, and lifecycle controls together. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Keep it simple and small in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 25

After a business change, Trey Research discovers that Zero trust or trust but verify is not handled consistently for the clinical records environment. The chief information security officer needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The architecture contains 72 separately managed trust zones or platform components.

  1. Use layered facility, environmental, fire, utility, power, and restricted-area controls to remove single points of physical failure.
  2. Identify the cryptanalytic or credential attack class and mitigate the exploited weakness rather than merely increasing unrelated perimeter controls.
  3. Document the risk as accepted without identifying an accountable risk owner or evaluating residual impact.
  4. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.

Correct answer: D

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Zero trust or trust but verify while preserving evidence needed for later review.

Option review:

A: Data-center security includes environmental resilience and life-safety controls as well as access barriers. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

B: Cryptographic and authentication attacks target specific weaknesses in algorithms, implementations, keys, protocols, or credentials. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Zero trust or trust but verify in this scenario.

D: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Zero trust or trust but verify while preserving evidence needed for later review.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Question 26

Margie Travel is preparing a security decision for the remote access service. The decision involves Privacy by design. The risk manager must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The architecture contains 89 separately managed trust zones or platform components.

  1. Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model.
  2. Select the security model whose rules match the required confidentiality or integrity objective, and implement the model consistently rather than mixing incompatible assumptions.
  3. Rely on a manual checklist performed during emergencies instead of establishing a repeatable preventive or detective control.
  4. Use the platform security capability that establishes the required trust property, such as hardware-backed key protection, memory isolation, or cryptographic enforcement.

Correct answer: A

Why: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Privacy by design without granting broader privilege than the business need requires.

Option review:

A: Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise. It directly addresses Privacy by design without granting broader privilege than the business need requires.

B: Formal security models express different protection goals; the model must match the property the system is required to preserve. That action can be useful in a different security decision, but it does not most directly address Privacy by design in this scenario.

C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Privacy by design in this scenario.

D: Built-in system capabilities can provide stronger trust anchors when they directly support the required security property. That action can be useful in a different security decision, but it does not most directly address Privacy by design in this scenario.

Learning point: Apply secure design principles such as least privilege, defense in depth, secure defaults, fail-secure behavior, separation of duties, and privacy by design according to the threat model. Secure architecture uses multiple reinforcing principles so the failure of one control does not become total compromise.

Popular posts

img