{"id":19067,"date":"2026-09-22T11:30:18","date_gmt":"2026-09-22T11:30:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19067"},"modified":"2026-09-22T11:30:18","modified_gmt":"2026-09-22T11:30:18","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 101.<\/b><\/p>\n<p><b>A security architect is evaluating whether a new application should use centralized or decentralized authorization. What should drive the decision MOST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The application&#8217;s font choices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Business requirements, trust boundaries, scale, and consistency needs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Developer preference alone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of office locations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Business requirements, trust boundaries, scale, and consistency needs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization architecture should reflect the system&#8217;s business requirements, trust model, operational scale, and need for consistent policy enforcement. Centralized authorization can simplify governance and policy consistency, while decentralized enforcement may provide flexibility or resilience in some designs. The architect should evaluate tradeoffs such as latency, availability, policy synchronization, and administrative complexity. The decision should be risk-based rather than driven by cosmetic or personal preferences.<\/span><\/p>\n<p><b>Question 102.<\/b><\/p>\n<p><b>Which security architecture principle MOST directly supports denying access when no explicit permission exists?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Fail-safe defaults<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Open design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Separation of duties<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Economy of mechanism<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Fail-safe defaults<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fail-safe defaults mean access should be denied unless it is explicitly permitted. This reduces the chance that missing or incomplete rules create unintended access. The principle is widely applied in firewalls, authorization systems, and network controls through default-deny policies. Open design concerns avoiding dependence on secrecy, separation of duties distributes sensitive responsibilities, and economy of mechanism favors simpler designs.<\/span><\/p>\n<p><b>Question 103.<\/b><\/p>\n<p><b>A security architect discovers that multiple applications share the same highly privileged service account. What is the BEST redesign?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the shared account&#8217;s privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable logging for the account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assign separate application identities with least-privilege permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Publish the password to all developers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assign separate application identities with least-privilege permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate application identities improve containment, accountability, and least privilege. If one application is compromised, its service identity should not automatically provide access to unrelated systems or data. Individual identities also make it easier to audit usage and revoke access selectively. A shared privileged account increases the blast radius of compromise and complicates investigations because actions cannot be attributed cleanly.<\/span><\/p>\n<p><b>Question 104.<\/b><\/p>\n<p><b>A highly available application depends on a single DNS service with no redundancy. What is the PRIMARY architectural concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS may use too much bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS names may be difficult to remember<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Users may prefer IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS represents a single point of failure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. DNS represents a single point of failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A highly available application can still fail if it relies on an unredundant supporting service. If the only DNS service becomes unavailable, users and application components may be unable to resolve required names even though the application servers remain healthy. Security and resilience architecture should identify critical dependencies and eliminate unnecessary single points of failure through appropriate redundancy and tested recovery mechanisms.<\/span><\/p>\n<p><b>Question 105.<\/b><\/p>\n<p><b>Which activity BEST helps a security architect understand where sensitive information enters, moves through, and leaves a system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data-flow analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Hardware inventory counting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Employee performance review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Software licensing audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data-flow analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data-flow analysis identifies how information moves among users, processes, applications, databases, external services, and networks. It helps architects locate trust boundaries and determine where encryption, validation, access control, logging, and other protections are needed. This is particularly important for sensitive or regulated information because security requirements may change as data crosses systems or organizational boundaries.<\/span><\/p>\n<p><b>Question 106.<\/b><\/p>\n<p><b>A business requires a critical application to continue operating even when one authentication server fails. Which approach is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one authentication server with more memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Deploy redundant authentication services and test failover<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication during failures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow anonymous access temporarily<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Deploy redundant authentication services and test failover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication can become a critical availability dependency. Redundant authentication services reduce the risk that failure of a single server prevents legitimate access. Failover should be tested so the organization knows that secondary components function correctly during disruption. Disabling authentication or permitting anonymous access would sacrifice security for availability and could create unacceptable risk.<\/span><\/p>\n<p><b>Question 107.<\/b><\/p>\n<p><b>A company is evaluating a SaaS provider that will process regulated information. Which issue should the security architect evaluate MOST carefully?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The provider&#8217;s office furniture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The application&#8217;s color scheme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data protection responsibilities, contractual controls, and assurance evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of sales representatives<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data protection responsibilities, contractual controls, and assurance evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a SaaS provider processes regulated information, the organization still retains responsibilities for protecting that data. The architect should evaluate contractual requirements, privacy obligations, access controls, encryption, incident notification, retention, deletion, and available assurance evidence. Clear responsibility boundaries reduce the risk of control gaps. Marketing and cosmetic factors are not meaningful substitutes for security due diligence.<\/span><\/p>\n<p><b>Question 108.<\/b><\/p>\n<p><b>A system cannot validate a digital certificate because the trust service is unavailable. For a high-assurance transaction, what is the safest behavior?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust the certificate automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Skip certificate validation temporarily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Accept the transaction if the user requests it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reject or defer the transaction until trust can be established**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Reject or defer the transaction until trust can be established<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High-assurance transactions should not proceed when the system cannot reliably validate the trust relationship. Automatically accepting an unverified certificate would weaken authentication and could expose the transaction to impersonation or interception. A fail-secure approach rejects or delays the transaction until certificate validity and trust can be confirmed. The availability tradeoff should be considered during architecture design.<\/span><\/p>\n<p><b>Question 109.<\/b><\/p>\n<p><b>What is the PRIMARY benefit of using a dedicated privileged-access workstation for administrators?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It reduces exposure of privileged credentials to ordinary user activity and threats<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees administrators cannot make mistakes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It reduces exposure of privileged credentials to ordinary user activity and threats<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged-access workstations separate sensitive administrative activity from routine browsing, email, and productivity tasks. This reduces the chance that malware or phishing targeting a normal user environment captures privileged credentials or sessions. They should still be combined with strong authentication, segmentation, monitoring, and controlled administrative paths. Dedicated workstations improve isolation but do not replace other safeguards.<\/span><\/p>\n<p><b>Question 110.<\/b><\/p>\n<p><b>A security architect must protect data exchanged between two internal services that communicate across an untrusted network segment. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network address translation only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Authenticated encryption for the service-to-service communication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Additional disk space<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data compression only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Authenticated encryption for the service-to-service communication<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authenticated encryption can protect both confidentiality and integrity while also helping verify that the communication endpoint is legitimate. Internal services should not automatically trust a network simply because it belongs to the organization. If the communication crosses an untrusted or shared segment, secure transport should protect data against interception and modification. NAT and compression do not provide equivalent protection.<\/span><\/p>\n<p><b>Question 111.<\/b><\/p>\n<p><b>A security architect wants to minimize the impact of compromise of a web application. Which design is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give the application broad access to all internal systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use one account for every application tier<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restrict the application to only required network paths and backend permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable application logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Restrict the application to only required network paths and backend permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Constraining both network connectivity and application permissions limits what an attacker can do after compromising the web application. The web tier should communicate only with required backend systems and use identities with narrowly scoped privileges. This combines segmentation and least privilege to reduce lateral movement and data exposure. Broad permissions would greatly increase the blast radius of compromise.<\/span><\/p>\n<p><b>Question 112.<\/b><\/p>\n<p><b>An organization wants evidence that sensitive administrative actions cannot be easily erased by the administrator performing them. Which design is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store audit logs only on the administered server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow administrators to delete their own logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable logging during maintenance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Send logs to a separately protected centralized system**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Send logs to a separately protected centralized system<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separately protected centralized logging reduces the ability of an administrator or attacker controlling one system to erase all evidence of activity. Logs should be access-controlled, time-synchronized, monitored, and retained appropriately. Local logs can still be useful, but an independent copy strengthens accountability and supports investigations. Administrators should not have unrestricted ability to alter evidence of their own actions.<\/span><\/p>\n<p><b>Question 113.<\/b><\/p>\n<p><b>Which principle MOST directly supports designing security mechanisms to be as simple as practical?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Economy of mechanism<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Complete mediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Separation of privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Psychological acceptability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Economy of mechanism<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Economy of mechanism favors simple and understandable security designs. Unnecessary complexity can introduce hidden dependencies, implementation defects, inconsistent configuration, and maintenance problems. Simpler mechanisms are generally easier to analyze, test, and operate correctly. This does not mean security systems should be simplistic; necessary complexity may be justified, but it should serve a clear requirement.<\/span><\/p>\n<p><b>Question 114.<\/b><\/p>\n<p><b>A system must preserve transaction integrity even if one administrator becomes malicious. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow one administrator full control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require independent approval for high-risk transactions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable transaction logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use one shared privileged account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Require independent approval for high-risk transactions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Independent approval applies separation of duties and, in some cases, dual control. It reduces the chance that one malicious or compromised administrator can complete a high-risk transaction without oversight. The design can also include strong auditing and individual identities. Shared accounts or unrestricted authority would weaken both accountability and resistance to insider misuse.<\/span><\/p>\n<p><b>Question 115.<\/b><\/p>\n<p><b>A business continuity analysis determines that a service can tolerate four hours of downtime but only ten minutes of data loss. What are the correct objectives?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTO ten minutes; RPO four hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RTO and RPO both four hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> RTO four hours; RPO ten minutes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> RTO and RPO both ten minutes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. RTO four hours; RPO ten minutes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective defines the maximum target time for restoring the service after disruption, so the RTO is four hours. The recovery point objective defines the acceptable amount of data loss measured in time, so the RPO is ten minutes. These objectives drive design decisions around replication, backup frequency, standby infrastructure, and recovery procedures.<\/span><\/p>\n<p><b>Question 116.<\/b><\/p>\n<p><b>A security architect finds that a business process depends on one external provider with no alternative. What architectural concern should be raised?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The provider may use a different logo<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The contract may be too long<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The provider may have too many employees<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The provider represents a concentration and availability risk**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The provider represents a concentration and availability risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A single external provider can become a critical dependency. If that provider experiences an outage, security incident, legal restriction, or business failure, the organization&#8217;s service may be disrupted. The architect should evaluate alternatives, contingency plans, contractual protections, recovery options, and the business impact of provider failure. External dependencies should be included in resilience and risk analysis.<\/span><\/p>\n<p><b>Question 117.<\/b><\/p>\n<p><b>A security architect wants to reduce exposure created by unnecessary network services. What should be done?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable or remove services and ports that are not required<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Enable every available service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permit unrestricted inbound traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give all systems public addresses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Disable or remove services and ports that are not required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unused services and ports expand attack surface without providing business value. Removing or disabling unnecessary functionality reduces opportunities for exploitation and makes systems easier to secure and monitor. This is a fundamental hardening practice. Required services should still be configured securely and restricted to the users, systems, and network paths that actually need them.<\/span><\/p>\n<p><b>Question 118.<\/b><\/p>\n<p><b>Which approach BEST supports secure federation between two organizations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Share one generic account between all users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establish defined trust, strong identity assertions, appropriate validation, and limited authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication at the trust boundary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted access after federation succeeds<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Establish defined trust, strong identity assertions, appropriate validation, and limited authorization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federation extends identity trust across organizational boundaries, so the trust relationship must be explicit and controlled. Identity assertions should be validated, authentication assurance should match the risk, and authorization should remain limited to required resources. Federation should not imply unrestricted trust. Logging, certificate or key management, and procedures for terminating the trust relationship are also important architectural considerations.<\/span><\/p>\n<p><b>Question 119.<\/b><\/p>\n<p><b>A security architect discovers that a legacy system cannot encrypt sensitive traffic. What should be done FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the weakness because the system is old<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Expose the system directly to the internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the risk and design compensating protection such as secure gateways or network isolation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable all monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the risk and design compensating protection such as secure gateways or network isolation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legacy limitations should be addressed through documented risk analysis rather than ignored. If the system cannot provide required cryptographic protection directly, compensating controls may include encrypted tunnels, secure proxies, segmentation, restricted access paths, or application gateways. Replacement may be the preferred long-term strategy, but interim safeguards should reduce exposure to an acceptable level based on business risk.<\/span><\/p>\n<p><b>Question 120.<\/b><\/p>\n<p><b>Which approach BEST demonstrates mature security architecture lifecycle management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve the design once and never review it again<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore changes in technology and threats<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Document only successful architecture decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reassess architecture when risks, business requirements, dependencies, or technologies materially change**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Reassess architecture when risks, business requirements, dependencies, or technologies materially change<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture is not static. New threats, cloud services, acquisitions, regulations, business processes, and technology changes can invalidate earlier assumptions. Mature lifecycle management includes periodic and event-driven reassessment, architecture reviews, documented exceptions, risk tracking, and validation of control effectiveness. Reassessment keeps the security architecture aligned with the organization&#8217;s current operating environment.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 101. A security architect is evaluating whether a new application should use centralized or decentralized authorization. What should drive the decision MOST? The application&#8217;s font choices 2. Business requirements, trust boundaries, scale, and consistency needs 3. Developer preference alone 4. The number of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19067"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19067"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19067\/revisions"}],"predecessor-version":[{"id":19068,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19067\/revisions\/19068"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}