{"id":19065,"date":"2026-09-22T11:29:50","date_gmt":"2026-09-22T11:29:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19065"},"modified":"2026-09-22T11:29:50","modified_gmt":"2026-09-22T11:29:50","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 81.<\/b><\/p>\n<p><b>A security architect is evaluating a new remote-access solution for privileged administrators. Which requirement should be prioritized MOST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Strong authentication, restricted access paths, and detailed auditing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Anonymous access during maintenance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared administrator credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Unrestricted access from any endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Strong authentication, restricted access paths, and detailed auditing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged remote access creates significant risk because compromise can lead directly to critical systems. The architecture should therefore use strong authentication, tightly controlled network paths, trusted administrative endpoints, least privilege, and protected logging. Shared credentials weaken accountability, while unrestricted or anonymous access increases attack surface. A well-designed privileged-access solution should make administrative activity both difficult to misuse and easy to trace.<\/span><\/p>\n<p><b>Question 82.<\/b><\/p>\n<p><b>A company wants to ensure that a single compromised application account cannot access every database in the environment. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one shared database account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use separate service identities with narrowly scoped permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Grant all application accounts database-administrator privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable database authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use separate service identities with narrowly scoped permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate application identities allow access to be limited to the specific databases, schemas, or functions each application needs. If one account is compromised, the attacker\u2019s reach is constrained. This applies least privilege and reduces the blast radius of credential theft. Shared or broadly privileged accounts increase risk and make accountability more difficult.<\/span><\/p>\n<p><b>Question 83.<\/b><\/p>\n<p><b>Which architecture activity BEST identifies where encryption, authentication, and validation controls should be placed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asset depreciation analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User-interface testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Trust-boundary and data-flow analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Capacity planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Trust-boundary and data-flow analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trust-boundary and data-flow analysis shows where information moves between users, systems, networks, applications, and external parties that have different trust assumptions. These transitions are natural locations for controls such as authentication, authorization, input validation, encryption, and monitoring. Understanding the flow of sensitive information is therefore fundamental to deciding where security controls should be enforced.<\/span><\/p>\n<p><b>Question 84.<\/b><\/p>\n<p><b>A critical service must remain available if an entire availability zone fails. Which design BEST supports this objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy all instances in one zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store backups on the same server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase the CPU capacity of one host<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Distribute redundant service components across independent zones**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Distribute redundant service components across independent zones<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Placing redundant components across independent availability zones reduces the chance that a localized infrastructure failure will disable the entire service. The architecture should also consider load balancing, data replication, network independence, and tested failover. Increasing the capacity of a single host does not protect against zone-wide failure. Resilience should address the failure domain defined by the business continuity requirement.<\/span><\/p>\n<p><b>Question 85.<\/b><\/p>\n<p><b>Which principle should guide the amount of information collected by a system when only a subset is needed for business processing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Maximum privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Default allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Open access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting and retaining only the information necessary for the defined business purpose. Reducing unnecessary data lowers privacy exposure, compliance burden, and potential breach impact. Sensitive information should not be collected merely because it may be useful someday. The architecture should align data collection with legitimate functional requirements and retention obligations.<\/span><\/p>\n<p><b>Question 86.<\/b><\/p>\n<p><b>An organization is implementing a hardware security module for cryptographic-key protection. What is the MOST important architectural concern for availability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The HSM&#8217;s physical color<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Avoiding a single point of failure while preserving key security<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Using the same key for all applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling audit logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Avoiding a single point of failure while preserving key security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security module may become critical infrastructure if authentication, encryption, or signing services depend on it. Redundant HSM capability, secure key synchronization or backup, and tested failover can improve availability. However, resilience must not weaken key protection. The architecture should balance confidentiality and integrity of key material with the need to survive device or site failures.<\/span><\/p>\n<p><b>Question 87.<\/b><\/p>\n<p><b>A proposed application uses a single privileged service account for multiple unrelated functions. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The account name may be too long<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The service may generate additional logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Excessive privilege increases the impact of account compromise<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The application may require more storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Excessive privilege increases the impact of account compromise<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A broadly privileged service account creates a large blast radius. If it is compromised, an attacker may gain access to multiple systems or functions unrelated to the original application need. Separating identities and granting only required permissions improves least privilege, accountability, and containment. The architecture should avoid concentrating unnecessary power in one credential.<\/span><\/p>\n<p><b>Question 88.<\/b><\/p>\n<p><b>A security control fails and the system cannot determine whether a user is authorized. Which response is MOST appropriate for a highly confidential resource?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow access until the control recovers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Grant temporary administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore authorization for read operations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Deny access until authorization can be verified**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Deny access until authorization can be verified<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For a highly confidential resource, failure of the authorization mechanism should normally result in a protected state. Denying access prevents the failure from becoming an unintended authorization bypass. This reflects fail-secure behavior and fail-safe defaults. Availability requirements still matter, but the security response should align with the priority of confidentiality and the organization&#8217;s risk tolerance.<\/span><\/p>\n<p><b>Question 89.<\/b><\/p>\n<p><b>What is the MAIN security advantage of isolating management interfaces from general user networks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It reduces attack surface and limits access to privileged control paths<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees administrators cannot make errors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It reduces attack surface and limits access to privileged control paths<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management interfaces provide powerful capabilities and should not be broadly reachable from ordinary user networks. Segmentation, jump hosts, dedicated administrative networks, and strong authentication reduce exposure and make privileged access easier to control. This isolation does not replace authentication or monitoring, but it provides an important additional layer of protection.<\/span><\/p>\n<p><b>Question 90.<\/b><\/p>\n<p><b>A security architect is comparing two designs that provide equivalent functionality. Which choice is generally preferable when both satisfy security requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The design with the greatest number of components<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The simpler design with fewer unnecessary dependencies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The design that is harder to document<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The design with the most vendors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The simpler design with fewer unnecessary dependencies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unnecessary complexity can introduce hidden dependencies, configuration errors, maintenance problems, and additional attack surface. When two solutions meet the same business and security requirements, a simpler design is often easier to understand, validate, operate, and secure. Complexity should be justified by a specific requirement rather than treated as inherently beneficial.<\/span><\/p>\n<p><b>Question 91.<\/b><\/p>\n<p><b>A security architect wants to protect a public API from excessive automated requests. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unlimited requests from all clients<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply rate limiting and appropriate request controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove audit logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Apply rate limiting and appropriate request controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting can reduce abuse, denial-of-service pressure, credential attacks, and excessive resource consumption by controlling how frequently clients may make requests. It should be combined with authentication, authorization, input validation, monitoring, and capacity protections. Removing authentication or allowing unlimited requests would increase rather than reduce the API&#8217;s exposure.<\/span><\/p>\n<p><b>Question 92.<\/b><\/p>\n<p><b>An organization outsources processing of sensitive data to a third party. Which architectural governance practice is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust the provider without verification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Avoid documenting security responsibilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permit unrestricted provider access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Establish contractual security requirements, assurance mechanisms, and responsibility boundaries**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Establish contractual security requirements, assurance mechanisms, and responsibility boundaries<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party processing creates shared security responsibilities that should be explicitly defined. Contracts and governance should address access, data handling, incident notification, privacy, audit rights, retention, destruction, and other applicable controls. Ongoing assurance helps confirm that the provider continues to meet requirements. Reliance on assumptions or informal agreements creates avoidable security gaps.<\/span><\/p>\n<p><b>Question 93.<\/b><\/p>\n<p><b>Why should threat modeling be performed early in the system-development lifecycle?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows architectural weaknesses and likely attack paths to be addressed before implementation becomes expensive to change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It guarantees that no vulnerabilities will remain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for penetration testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces risk management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It allows architectural weaknesses and likely attack paths to be addressed before implementation becomes expensive to change<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling helps identify assets, trust boundaries, likely attackers, abuse cases, and attack paths while the architecture is still flexible. Fixing design flaws early is generally less expensive than correcting them after deployment. Threat modeling complements rather than replaces later testing and ongoing risk management. It provides a structured way to build security into the design from the beginning.<\/span><\/p>\n<p><b>Question 94.<\/b><\/p>\n<p><b>A business requires a system to be restored within one hour after disruption while tolerating up to five minutes of data loss. Which statement is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTO is five minutes and RPO is one hour<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTO is one hour and RPO is five minutes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Both RTO and RPO are one hour<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Both RTO and RPO are five minutes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. RTO is one hour and RPO is five minutes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective defines how quickly the service must be restored after a disruption, so the RTO is one hour. The recovery point objective defines the maximum acceptable amount of data loss, expressed as time, so the RPO is five minutes. These values guide architecture decisions related to replication, backups, standby environments, and recovery processes.<\/span><\/p>\n<p><b>Question 95.<\/b><\/p>\n<p><b>Which design BEST limits lateral movement after compromise of an internet-facing web server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Put all systems in the same subnet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted east-west traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Segment application tiers and permit only explicitly required communications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authentication between tiers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Segment application tiers and permit only explicitly required communications<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segmentation limits the ability of a compromised web server to reach application, database, administrative, or unrelated systems. Explicitly permitting only required traffic reduces potential attack paths and applies a default-deny philosophy. Authentication and authorization between components should remain in place as additional security layers. Flat networks increase the blast radius of compromise.<\/span><\/p>\n<p><b>Question 96.<\/b><\/p>\n<p><b>A security architect discovers that application encryption keys are embedded directly in source code. What is the BEST corrective action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep the keys in source code but rename the variables<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Add comments warning developers not to copy them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use longer source-code files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Move keys to an approved secure key-management mechanism**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Move keys to an approved secure key-management mechanism<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Embedding cryptographic keys in source code makes them difficult to rotate and exposes them to developers, repositories, build systems, and anyone who gains code access. Keys should be generated, stored, accessed, rotated, and revoked through an approved key-management solution. Separating key material from application code reduces exposure and supports stronger lifecycle management.<\/span><\/p>\n<p><b>Question 97.<\/b><\/p>\n<p><b>What is the PRIMARY benefit of defining security architecture principles at the enterprise level?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They provide consistent guidance for security decisions across projects<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They eliminate the need for risk analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> They force every application to use identical technology<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> They replace security policies entirely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. They provide consistent guidance for security decisions across projects<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise architecture principles establish common expectations for areas such as least privilege, segmentation, encryption, resilience, and secure administration. They help teams make consistent decisions and reduce repeated design errors. Principles should still be applied in a risk-based manner and do not remove the need for policies, standards, or project-specific analysis.<\/span><\/p>\n<p><b>Question 98.<\/b><\/p>\n<p><b>A system design requires one person to request a sensitive transaction and another person to approve it. Which security concept is MOST directly applied?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Fail open<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Separation of duties<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network redundancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Separation of duties<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides critical responsibilities so that a single individual cannot independently complete a sensitive process. Requiring one person to initiate a transaction and another to approve it reduces the risk of fraud, error, and abuse. This concept is closely related to dual control, particularly when multiple individuals must participate in a high-impact action.<\/span><\/p>\n<p><b>Question 99.<\/b><\/p>\n<p><b>An enterprise security architecture includes many legacy systems that cannot support modern authentication. What should the architect do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the systems because they are old<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Expose them directly to the internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the risk and design compensating controls around the legacy limitations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the risk and design compensating controls around the legacy limitations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legacy constraints do not remove the underlying security requirement. The architect should assess the risk created by weak authentication and determine whether compensating controls such as network isolation, controlled access gateways, stronger upstream authentication, monitoring, or reduced privileges can lower risk to an acceptable level. Replacement may be a long-term objective, but interim protection should be based on documented risk.<\/span><\/p>\n<p><b>Question 100.<\/b><\/p>\n<p><b>Which practice BEST demonstrates mature enterprise security architecture management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve architectures once and never revisit them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow undocumented exceptions whenever projects request them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review security only after breaches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain standards, assess designs, track exceptions and risks, and periodically reassess architecture effectiveness**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain standards, assess designs, track exceptions and risks, and periodically reassess architecture effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mature architecture management is continuous. Standards and principles provide direction, design reviews identify weaknesses, exception processes document justified deviations, and risk tracking creates accountability. Periodic reassessment is necessary because technologies, threats, regulations, and business requirements change over time. Treating architecture as a one-time approval process allows controls and assumptions to become outdated.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 81. A security architect is evaluating a new remote-access solution for privileged administrators. Which requirement should be prioritized MOST? Strong authentication, restricted access paths, and detailed auditing 2. Anonymous access during maintenance 3. Shared administrator credentials 4. Unrestricted access from any endpoint Correct [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19065"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19065"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19065\/revisions"}],"predecessor-version":[{"id":19066,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19065\/revisions\/19066"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}