{"id":19059,"date":"2026-09-22T11:25:21","date_gmt":"2026-09-22T11:25:21","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19059"},"modified":"2026-09-22T11:25:21","modified_gmt":"2026-09-22T11:25:21","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 21.<\/b><\/p>\n<p><b>A security architect is designing a new payment-processing environment. Which action should occur BEFORE selecting specific security products?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Define business, security, compliance, and risk requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Purchase the most widely used firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Configure production logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Conduct a post-implementation penetration test<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Define business, security, compliance, and risk requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security products should be selected only after the architect understands what the environment must protect and which risks must be addressed. Business objectives, regulatory obligations, data sensitivity, availability requirements, and organizational risk tolerance all influence the security architecture. Choosing technologies too early can lead to controls that are poorly aligned with actual requirements. Penetration testing and production configuration occur later in the lifecycle, after the architecture and implementation have been established.<\/span><\/p>\n<p><b>Question 22.<\/b><\/p>\n<p><b>An organization wants to reduce the possibility that one administrator can make an unauthorized high-risk change without oversight. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Separation of duties<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data replication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Separation of duties<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among multiple individuals so that one person cannot independently complete a high-risk process. For example, one administrator may request a privileged change while another approves it. This helps reduce fraud, error, and misuse of administrative authority. Single sign-on improves authentication convenience, while replication and NAT address different technical concerns. Separation of duties directly supports governance over sensitive administrative actions.<\/span><\/p>\n<p><b>Question 23.<\/b><\/p>\n<p><b>A security architect must design controls for an application containing highly confidential intellectual property. Which factor should have the GREATEST influence on the architecture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User-interface design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Vendor market share<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Business impact and information classification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Number of application developers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Business impact and information classification<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information classification and business impact help determine the level of confidentiality, integrity, and availability protection required. Highly sensitive intellectual property may justify stronger authentication, encryption, segmentation, monitoring, and access restrictions than lower-value data. Vendor popularity or team size should not override risk-based requirements. A security architect should trace control selection back to the value of the assets and the consequences of compromise.<\/span><\/p>\n<p><b>Question 24.<\/b><\/p>\n<p><b>Which architecture BEST protects an internal database from direct internet exposure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place the database and web server in the same public subnet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow inbound internet traffic directly to the database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable network filtering between application tiers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Separate web, application, and database tiers with controlled communication between them**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Separate web, application, and database tiers with controlled communication between them<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tiered segmentation limits the systems that can communicate directly with sensitive backend services. An internet-facing web tier can be separated from application and database tiers, with only necessary traffic allowed between them. This reduces attack paths and supports defense in depth. Exposing the database directly or placing all components in the same unrestricted segment would increase the impact of a compromised internet-facing system.<\/span><\/p>\n<p><b>Question 25.<\/b><\/p>\n<p><b>A company wants security controls to continue protecting critical resources even if one mechanism fails. Which architectural principle BEST supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Default allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Single-point enforcement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Defense in depth<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary safeguards so that the failure of one control does not leave the asset completely unprotected. For example, identity controls, network segmentation, endpoint protection, application authorization, encryption, and monitoring can work together. Shared accounts and default-allow policies weaken security. A single control creates a potential single point of failure, which is the opposite of layered protection.<\/span><\/p>\n<p><b>Question 26.<\/b><\/p>\n<p><b>Which security design principle requires an account to receive only the access needed to perform its assigned function?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Fail-safe defaults<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Open design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Complete mediation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Least privilege<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits users, processes, and services to the minimum permissions required for legitimate tasks. This reduces the damage that can result from mistakes, malicious activity, or account compromise. Privileges should also be reviewed and removed when they are no longer needed. Although fail-safe defaults and complete mediation are important security principles, least privilege specifically addresses limiting the scope of granted access.<\/span><\/p>\n<p><b>Question 27.<\/b><\/p>\n<p><b>A security architect is reviewing a proposed cloud solution. Which issue is MOST important for determining who must implement specific security controls?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The cloud provider&#8217;s office locations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The graphical design of the administration portal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The shared-responsibility model for the selected cloud service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of customer support representatives<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The shared-responsibility model for the selected cloud service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The shared-responsibility model defines which security responsibilities belong to the cloud provider and which remain with the customer. The division varies among infrastructure, platform, and software service models. Architects must understand responsibility for identity, configuration, data protection, operating systems, network controls, logging, and other safeguards. Ambiguous ownership can leave critical controls unimplemented, making this an essential cloud architecture consideration.<\/span><\/p>\n<p><b>Question 28.<\/b><\/p>\n<p><b>A critical service must continue operating after the loss of an entire primary data center. Which design BEST supports this objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store backups in the same data center<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Add a second server in the same rack<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one highly powerful production server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Implement geographically separated recovery or redundant processing capability**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Implement geographically separated recovery or redundant processing capability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A site-wide outage can affect power, networking, facilities, and all systems located within the same data center. Geographic separation reduces this common-mode failure risk. Depending on recovery requirements, organizations may use active-active, active-passive, or other resilient designs across sites. Local redundancy protects against individual component failures but may not survive a complete data-center outage.<\/span><\/p>\n<p><b>Question 29.<\/b><\/p>\n<p><b>Which action BEST supports secure management of cryptographic keys?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Define controlled generation, storage, rotation, revocation, and destruction procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store all private keys in plaintext for easy recovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one encryption key permanently for all systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Email keys to administrators when needed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Define controlled generation, storage, rotation, revocation, and destruction procedures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic security depends heavily on key management. Even strong algorithms can be undermined if keys are exposed, reused indefinitely, or poorly controlled. A sound architecture addresses the full key lifecycle, including generation, distribution, secure storage, rotation, recovery where appropriate, revocation, and destruction. Key access should be restricted and auditable. Storing or transmitting private keys insecurely creates a serious compromise risk.<\/span><\/p>\n<p><b>Question 30.<\/b><\/p>\n<p><b>An organization wants to reduce its reliance on trusted internal network locations when making access decisions. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Flat internal networking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Zero Trust architecture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Perimeter-only filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Anonymous internal access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Zero Trust architecture<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust does not automatically trust users or devices simply because they are inside the corporate network. Access decisions are based on identity, device condition, context, policy, and resource sensitivity. Continuous verification and least-privilege access are central ideas. A flat network or perimeter-only model can provide excessive implicit trust once an attacker enters the internal environment.<\/span><\/p>\n<p><b>Question 31.<\/b><\/p>\n<p><b>A security architect is designing an administrative interface for highly sensitive infrastructure. Which control BEST reduces the risk of exposing the interface to unauthorized users?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow access from any internet address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use only a complex URL<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restrict management access to authorized administrative networks and strong authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable audit logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Restrict management access to authorized administrative networks and strong authentication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitive management interfaces should have limited exposure and require strong authentication. Restricting administrative access to controlled networks, secure access paths, or approved management systems reduces attack surface. Multi-factor authentication and detailed logging can provide additional protection. A hidden URL is not a meaningful access control, while broad internet exposure and disabled logging increase risk.<\/span><\/p>\n<p><b>Question 32.<\/b><\/p>\n<p><b>An organization is designing a system where failure of an access-control component must not unintentionally grant access. Which behavior is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Default allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous fallback<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Fail secure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Fail secure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fail-secure design means that when a security mechanism fails, the system moves toward a protected state rather than granting unauthorized access. For access control, this usually means denying requests when policy cannot be evaluated reliably. The exact implementation must consider availability requirements, but granting access automatically during a security-control failure can create serious exposure. This principle is closely related to fail-safe defaults.<\/span><\/p>\n<p><b>Question 33.<\/b><\/p>\n<p><b>Which activity BEST helps an architect identify trust boundaries within a new application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data-flow and component interaction analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reviewing employee vacation schedules<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Counting source-code files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Measuring processor utilization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data-flow and component interaction analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trust boundaries occur where data, processes, users, or systems move between areas with different security assumptions or levels of trust. Data-flow analysis helps architects see where information enters, leaves, or crosses between application components, networks, users, and external services. These transitions are important locations for authentication, authorization, validation, encryption, and monitoring controls. Operational metrics such as processor utilization do not identify trust boundaries.<\/span><\/p>\n<p><b>Question 34.<\/b><\/p>\n<p><b>What is the MAIN security purpose of strong authentication for privileged administrators?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase network bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reduce the likelihood that stolen or guessed credentials alone enable privileged access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Eliminate authorization policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Replace audit logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Reduce the likelihood that stolen or guessed credentials alone enable privileged access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged accounts can make high-impact changes, so authentication assurance should generally be stronger than for ordinary access. Multi-factor authentication, protected administrative channels, and dedicated privileged identities can reduce the likelihood that a single compromised password results in administrative access. Authentication does not replace authorization or auditing; all three contribute to controlling and monitoring privileged activity.<\/span><\/p>\n<p><b>Question 35.<\/b><\/p>\n<p><b>A security architect wants to minimize the amount of sensitive personal data stored by an application. Which principle is being applied?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Nonrepudiation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting, processing, and retaining only the information necessary for a legitimate purpose. Reducing the amount of sensitive data stored can decrease privacy exposure and the impact of a breach. It can also reduce compliance and protection requirements. Defense in depth and high availability address different architectural concerns, while nonrepudiation focuses on providing evidence that an action occurred.<\/span><\/p>\n<p><b>Question 36.<\/b><\/p>\n<p><b>Which design is MOST appropriate when an organization requires an independent record of administrator actions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable privileged logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow administrators to modify their own logs freely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store logs only on the administered system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Send security logs to a protected centralized logging system**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Send security logs to a protected centralized logging system<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized protected logging makes it more difficult for an administrator or attacker who compromises one system to erase all evidence of activity. Logs should be access-controlled, time-synchronized, monitored, and retained according to organizational requirements. Keeping the only copy locally increases the risk of tampering or loss. Independent logging strengthens accountability, investigations, and security monitoring.<\/span><\/p>\n<p><b>Question 37.<\/b><\/p>\n<p><b>What is the BEST reason to conduct threat modeling during architecture design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify likely attack paths and select controls before implementation is complete<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace all penetration testing permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Determine employee compensation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Guarantee that no vulnerabilities will remain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Identify likely attack paths and select controls before implementation is complete<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling helps teams understand assets, trust boundaries, potential attackers, attack paths, and security weaknesses while the system is still being designed. Discovering risks early makes it easier and less expensive to address them through architecture changes. Threat modeling complements rather than replaces later security testing. It improves design quality but cannot guarantee that every vulnerability will be identified or eliminated.<\/span><\/p>\n<p><b>Question 38.<\/b><\/p>\n<p><b>A business requires an application to recover within two hours after a major outage. Which requirement does this MOST directly describe?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recovery point objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recovery time objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Maximum data classification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Mean time between failures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Recovery time objective<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective, or RTO, describes the target amount of time within which a system or business process should be restored after a disruption. A two-hour recovery requirement therefore defines an RTO. By contrast, the recovery point objective concerns the acceptable amount of data loss measured in time. Architects use both values to design suitable resilience, backup, replication, and recovery capabilities.<\/span><\/p>\n<p><b>Question 39.<\/b><\/p>\n<p><b>A business can tolerate no more than 15 minutes of transaction data loss after a disaster. Which metric does this define?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mean time to repair<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recovery time objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Recovery point objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Service level agreement duration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Recovery point objective<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery point objective, or RPO, specifies how much data loss the organization can tolerate, usually expressed as a period of time. An RPO of 15 minutes means recovery mechanisms should generally allow the organization to restore data to a point no more than 15 minutes before the disruption. This requirement influences backup and replication frequency. RTO, by contrast, addresses how quickly service must be restored.<\/span><\/p>\n<p><b>Question 40.<\/b><\/p>\n<p><b>Which approach BEST supports long-term security architecture governance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow every project to define security independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review security only after incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Avoid documenting accepted risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain architecture standards, conduct design reviews, document exceptions, and track risk decisions**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain architecture standards, conduct design reviews, document exceptions, and track risk decisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective architecture governance provides consistent principles and standards while allowing justified exceptions through a controlled process. Design reviews help identify security issues before implementation, and documented exceptions ensure that deviations are consciously evaluated rather than overlooked. Tracking accepted risks provides accountability and supports future reassessment. Governance should remain active throughout the system lifecycle rather than occurring only after security incidents.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 21. A security architect is designing a new payment-processing environment. Which action should occur BEFORE selecting specific security products? Define business, security, compliance, and risk requirements 2. Purchase the most widely used firewall 3. Configure production logging 4. Conduct a post-implementation penetration test [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19059"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19059"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19059\/revisions"}],"predecessor-version":[{"id":19060,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19059\/revisions\/19060"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}