{"id":19069,"date":"2026-09-22T11:30:45","date_gmt":"2026-09-22T11:30:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19069"},"modified":"2026-09-22T11:30:45","modified_gmt":"2026-09-22T11:30:45","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 121.<\/b><\/p>\n<p><b>A security architect is reviewing a new microservices design. Which architectural concern should be addressed FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The color scheme of each service dashboard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust relationships, service identities, and permitted communication paths<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of developers assigned to each service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The size of the source-code repository<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Trust relationships, service identities, and permitted communication paths<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microservices introduce many service-to-service interactions, making trust and identity important architectural concerns. Each service should have a defined identity, narrowly scoped permissions, and only the network access required to perform its function. The architect should also understand where sensitive data flows and which trust boundaries exist. Cosmetic and staffing details do not meaningfully determine the security posture of the service architecture.<\/span><\/p>\n<p><b>Question 122.<\/b><\/p>\n<p><b>Which security principle requires that mechanisms protect themselves against unauthorized modification?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Open design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Tamper resistance and protected security mechanisms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Tamper resistance and protected security mechanisms<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security controls must themselves be protected from unauthorized changes. If attackers can disable logging, modify access rules, alter security agents, or replace trusted configuration, the controls cannot be relied upon. Architectures should therefore protect administrative interfaces, configuration files, keys, and security components through access restrictions, integrity controls, monitoring, and appropriate separation. Least privilege helps support this goal but does not fully describe it.<\/span><\/p>\n<p><b>Question 123.<\/b><\/p>\n<p><b>A company wants administrators to access production servers only through a hardened intermediate system. What architectural component BEST fits this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Jump host or bastion system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Public DNS server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Content delivery network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> General-purpose user workstation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Jump host or bastion system<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A jump host or bastion system provides a controlled administrative access path into sensitive environments. It can enforce strong authentication, session monitoring, logging, and network restrictions while reducing direct exposure of production management interfaces. The bastion itself should be hardened and closely monitored. General user workstations should not normally have unrestricted direct access to critical production systems.<\/span><\/p>\n<p><b>Question 124.<\/b><\/p>\n<p><b>A highly sensitive application depends on one encryption-key server. What is the PRIMARY architectural risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The key server may produce too many logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Encryption may increase processor usage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Administrators may need additional training<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The key server may become a single point of failure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The key server may become a single point of failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If all cryptographic operations depend on one key-management component, failure of that component can make data or services unavailable even if the rest of the infrastructure remains healthy. High-assurance architectures should consider secure redundancy, backup, recovery, and tested failover while ensuring that key protection is not weakened. Resilience and security must be designed together.<\/span><\/p>\n<p><b>Question 125.<\/b><\/p>\n<p><b>A security architect wants to ensure that authentication and authorization decisions remain independent. Why is this useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows identity verification and access permission decisions to be controlled separately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for user identities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It removes the need for audit logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It guarantees every authenticated user full access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It allows identity verification and access permission decisions to be controlled separately<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication establishes who a user or service is, while authorization determines what that identity may do. Separating these functions supports flexible policy enforcement and prevents the mistaken assumption that successful authentication automatically grants broad access. An architecture should verify identity strongly and then apply least-privilege authorization based on roles, attributes, context, or other approved policy criteria.<\/span><\/p>\n<p><b>Question 126.<\/b><\/p>\n<p><b>An organization is designing disaster recovery for a database with a five-minute RPO. Which capability is MOST likely required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monthly full backups only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Frequent replication or backup mechanisms capable of meeting the five-minute data-loss target<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A single local backup stored beside the database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No backup because the database is highly available<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Frequent replication or backup mechanisms capable of meeting the five-minute data-loss target<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A five-minute RPO means the organization cannot tolerate losing more than approximately five minutes of data. The recovery architecture must therefore capture changes frequently enough to meet that requirement, often through replication, continuous protection, or frequent transaction backups. High availability does not replace data recovery, and infrequent backups would not satisfy such a strict RPO.<\/span><\/p>\n<p><b>Question 127.<\/b><\/p>\n<p><b>A security architect finds that an application accepts data from an external partner without validating input. What is the MAIN risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Higher storage costs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Slower network performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Malicious or malformed data may cross a trust boundary and affect internal systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The application may generate too few logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Malicious or malformed data may cross a trust boundary and affect internal systems<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">External input should be treated as untrusted. Without validation, malformed or malicious data may trigger injection, parsing failures, logic abuse, or other vulnerabilities in internal components. Validation should occur at appropriate trust boundaries and be based on expected formats and values. The architect should not rely on the external partner to guarantee safe input.<\/span><\/p>\n<p><b>Question 128.<\/b><\/p>\n<p><b>An organization wants to avoid exposing internal services directly to external clients. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place all internal services on public addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow clients to connect directly to databases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove network filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use a controlled gateway or proxy layer between external clients and internal services**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use a controlled gateway or proxy layer between external clients and internal services<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A gateway or proxy can provide a controlled trust boundary between external clients and internal services. It can enforce authentication, authorization, protocol validation, rate limiting, logging, and other protections before requests reach internal systems. Directly exposing internal services increases attack surface and makes policy enforcement more difficult. The gateway itself should also be hardened and resilient.<\/span><\/p>\n<p><b>Question 129.<\/b><\/p>\n<p><b>Why is configuration management important to security architecture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It helps ensure approved security settings remain consistent and unauthorized changes are detected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates all software vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces access control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents the need for system updates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It helps ensure approved security settings remain consistent and unauthorized changes are detected<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture depends on controls being implemented as designed. Configuration management helps maintain approved baselines, detect drift, document changes, and reduce inconsistent security settings. Without configuration control, systems can gradually deviate from the intended architecture. It complements vulnerability management, access control, monitoring, and change management rather than replacing them.<\/span><\/p>\n<p><b>Question 130.<\/b><\/p>\n<p><b>A business wants to reduce the impact of compromise of one cloud workload identity. Which design is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every workload the same broad cloud role<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assign separate workload identities with narrowly scoped permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable cloud audit logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use one permanent administrator credential for all workloads<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Assign separate workload identities with narrowly scoped permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate workload identities reduce the blast radius of compromise by limiting each service to the cloud resources and actions it actually requires. This supports least privilege and improves accountability. Broad shared roles make it easier for an attacker who compromises one workload to reach unrelated systems. Cloud identities should also be monitored and rotated or managed through appropriate platform mechanisms.<\/span><\/p>\n<p><b>Question 131.<\/b><\/p>\n<p><b>Which architecture characteristic MOST supports nonrepudiation for high-value digital transactions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Strong identity, protected audit evidence, and appropriate digital signatures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabled transaction logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Strong identity, protected audit evidence, and appropriate digital signatures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Nonrepudiation requires credible evidence linking an action or transaction to a specific party. Strong identity assurance, protected audit records, timestamps, and digital signatures can provide this evidence when properly implemented. Shared or anonymous credentials undermine attribution. The design must also protect signing keys and audit records from unauthorized alteration.<\/span><\/p>\n<p><b>Question 132.<\/b><\/p>\n<p><b>A security architect is designing a system in which policy enforcement must continue during a network partition. Which issue should be considered MOST carefully?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User-interface color<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Server rack placement only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of application icons<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The tradeoff between local policy enforcement, consistency, and availability**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The tradeoff between local policy enforcement, consistency, and availability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">During a network partition, centralized policy services may become unavailable. The architecture must decide whether local cached policies can be used, how stale they may become, and whether access should fail secure. These choices affect security, consistency, and availability. The correct design depends on data sensitivity, risk tolerance, and business requirements rather than cosmetic or physical details.<\/span><\/p>\n<p><b>Question 133.<\/b><\/p>\n<p><b>What is the MAIN advantage of using immutable infrastructure for security-sensitive workloads?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can reduce configuration drift by replacing systems rather than modifying them in place<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for patching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees applications have no vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for access controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It can reduce configuration drift by replacing systems rather than modifying them in place<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable infrastructure treats deployed systems as replaceable artifacts rather than environments that are continually modified. Updates are introduced by deploying new approved images or instances. This can reduce configuration drift and improve consistency, although the underlying images still require patching, vulnerability management, access control, and testing. Immutability is a useful architectural practice but not a complete security solution.<\/span><\/p>\n<p><b>Question 134.<\/b><\/p>\n<p><b>A business requires sensitive workloads to run only on approved managed devices. Which control BEST supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Device posture assessment integrated with access policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Open wireless access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Device posture assessment integrated with access policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture assessment can evaluate whether an endpoint meets security requirements such as managed status, encryption, patch level, endpoint protection, or certificate possession. Integrating device posture with access decisions allows the organization to restrict sensitive resources to trusted or compliant devices. This aligns with contextual and Zero Trust access models rather than relying solely on user identity.<\/span><\/p>\n<p><b>Question 135.<\/b><\/p>\n<p><b>An application is designed so that every component has direct access to every other component. What is the PRIMARY security weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The architecture may use too much encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The application may have too many users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compromise of one component can enable excessive lateral movement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Logging may become too centralized<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Compromise of one component can enable excessive lateral movement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unrestricted east-west communication creates a large blast radius. If one component is compromised, an attacker may be able to reach many unrelated systems. Segmentation, service identities, least privilege, and explicit communication policies can reduce lateral movement. Components should communicate only with the services and resources required for their function.<\/span><\/p>\n<p><b>Question 136.<\/b><\/p>\n<p><b>A security architect is assessing whether to allow a legacy application exception to an enterprise standard. What should be done FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve the exception automatically because the application is old<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the enterprise standard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Permanently disable monitoring for the application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Evaluate the risk, business need, compensating controls, and duration of the exception**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Evaluate the risk, business need, compensating controls, and duration of the exception<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exceptions should be deliberate and risk-based. The architect should understand why the standard cannot be met, the risk introduced, available compensating controls, and whether the exception should expire or be reviewed later. Documented approval creates accountability. Automatically granting permanent exceptions allows technical debt and risk to accumulate without oversight.<\/span><\/p>\n<p><b>Question 137.<\/b><\/p>\n<p><b>Why should an enterprise architecture identify critical security dependencies such as identity, DNS, certificate services, and key management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failure of shared dependencies can affect many otherwise healthy applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared services are always insecure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Applications should never use centralized services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Dependencies eliminate the need for resilience planning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Failure of shared dependencies can affect many otherwise healthy applications<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Applications may appear resilient while still depending on centralized services such as identity providers, DNS, certificate validation, or key management. Failure of one shared dependency can affect many systems simultaneously. Architects should identify these dependencies, evaluate concentration risk, provide appropriate redundancy, and test recovery behavior. Resilience must include supporting services, not just the application itself.<\/span><\/p>\n<p><b>Question 138.<\/b><\/p>\n<p><b>A security architect wants to ensure that only authorized software can be deployed to production. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow direct developer access to production servers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use a controlled deployment pipeline with approvals and integrity verification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share production administrator passwords with the development team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable deployment logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use a controlled deployment pipeline with approvals and integrity verification<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A controlled deployment pipeline can enforce code integrity, approval requirements, automated security checks, and separation between development and production. It reduces the need for broad direct administrative access and makes production changes more traceable. Integrity verification also helps ensure that deployed artifacts match approved versions. Logging should remain enabled to support accountability.<\/span><\/p>\n<p><b>Question 139.<\/b><\/p>\n<p><b>A system processes transactions that must not be altered undetected. Which security objective is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Availability only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Confidentiality only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Integrity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Convenience<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Integrity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity protects information and transactions against unauthorized or undetected modification. Controls may include cryptographic integrity protection, digital signatures, access controls, transaction validation, and protected audit logging. Confidentiality may also be necessary, but the stated requirement focuses specifically on detecting or preventing changes to transaction data. Architecture should align controls with the security objective that matters most to the business process.<\/span><\/p>\n<p><b>Question 140.<\/b><\/p>\n<p><b>Which practice BEST supports sustainable enterprise security architecture over time?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Design once and never reassess assumptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit permanent undocumented exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review only technical controls after a breach<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain standards, track dependencies and exceptions, reassess risk, and update architecture as requirements change**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain standards, track dependencies and exceptions, reassess risk, and update architecture as requirements change<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise security architecture must evolve as technologies, threats, regulations, dependencies, and business priorities change. Mature governance includes standards, architecture reviews, documented exceptions, dependency analysis, and periodic or event-driven risk reassessment. This allows the architecture to remain relevant instead of becoming outdated. Sustainable security depends on lifecycle management rather than one-time design approval.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 121. A security architect is reviewing a new microservices design. Which architectural concern should be addressed FIRST? The color scheme of each service dashboard 2. Trust relationships, service identities, and permitted communication paths 3. The number of developers assigned to each service 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19069"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19069"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19069\/revisions"}],"predecessor-version":[{"id":19070,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19069\/revisions\/19070"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}