{"id":19077,"date":"2026-09-22T11:32:08","date_gmt":"2026-09-22T11:32:08","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19077"},"modified":"2026-09-22T11:32:08","modified_gmt":"2026-09-22T11:32:08","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 201.<\/b><\/p>\n<p><b>A security architect is designing a new enterprise application that will process confidential data across several business units. What should be established FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security requirements derived from business objectives, data sensitivity, and risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The preferred firewall vendor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The final penetration-testing schedule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The production server naming convention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Security requirements derived from business objectives, data sensitivity, and risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Architecture should begin with requirements rather than specific technologies. The architect needs to understand business objectives, information classification, regulatory obligations, trust boundaries, availability expectations, and risk tolerance. These factors determine what security capabilities are necessary. Selecting products before defining requirements can produce controls that are expensive yet poorly aligned with actual risk. Testing schedules and naming conventions are implementation considerations that follow the architecture.<\/span><\/p>\n<p><b>Question 202.<\/b><\/p>\n<p><b>A critical application uses a centralized authorization service. Which design BEST improves resilience without abandoning centralized policy governance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit all access whenever the authorization service is unavailable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Provide redundant authorization services with clearly defined fail-secure behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authorization for internal users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store administrator passwords in the application configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Provide redundant authorization services with clearly defined fail-secure behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A centralized authorization service can become a critical dependency. Redundant service instances reduce availability risk while preserving consistent policy enforcement. The application should also have explicitly defined behavior if authorization cannot be verified, particularly for sensitive operations. Automatically allowing access during an outage creates a security bypass. Resilience should therefore be designed together with secure failure behavior rather than sacrificing authorization for availability.<\/span><\/p>\n<p><b>Question 203.<\/b><\/p>\n<p><b>An organization wants to reduce the risk created by administrators using powerful credentials for email and web browsing. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every administrator one permanent global account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable endpoint protection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use separate privileged identities and dedicated administrative workstations or sessions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permit privileged login from any unmanaged device<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use separate privileged identities and dedicated administrative workstations or sessions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating privileged administration from routine user activity reduces exposure of powerful credentials to phishing, malicious websites, email attachments, and ordinary endpoint threats. Dedicated administrative workstations, jump hosts, strong authentication, and separate privileged identities can significantly reduce this risk. Privileged access should also be logged and restricted through controlled network paths. A single broadly used administrator account increases the consequences of compromise.<\/span><\/p>\n<p><b>Question 204.<\/b><\/p>\n<p><b>A security architect discovers that all production systems depend on a single time-synchronization source. What is the PRIMARY concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Time synchronization may increase bandwidth use<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Users may see different time zones<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Logs may contain timestamps<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The time source represents a shared dependency and potential single point of failure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The time source represents a shared dependency and potential single point of failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Time synchronization is important for authentication, certificate validation, distributed transactions, monitoring, and forensic analysis. If every production system depends on one source, failure or compromise of that source could affect many services simultaneously. The architect should consider resilient and trustworthy time sources, appropriate hierarchy, monitoring, and protection against unauthorized changes. Shared infrastructure dependencies should be included in resilience planning.<\/span><\/p>\n<p><b>Question 205.<\/b><\/p>\n<p><b>Which architectural practice BEST reduces the exposure of sensitive databases to compromised web servers?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place database systems in a separate security zone and permit only required application flows<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted traffic between all tiers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable database authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Place databases directly on the internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Place database systems in a separate security zone and permit only required application flows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating database systems from internet-facing components limits direct attack paths and lateral movement. Only explicitly required traffic from approved application components should be permitted. This approach supports segmentation, least privilege, and defense in depth. Database authentication and authorization should remain enabled as additional controls. A flat network greatly increases the blast radius if a public-facing system is compromised.<\/span><\/p>\n<p><b>Question 206.<\/b><\/p>\n<p><b>An application must authenticate machine identities at very large scale. Which factor is MOST important when designing certificate-based authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The visual format of certificates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automated issuance, renewal, revocation, and private-key protection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of application logos<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> User password length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Automated issuance, renewal, revocation, and private-key protection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Large-scale certificate authentication depends on reliable lifecycle automation. Certificates must be issued securely, renewed before expiration, revoked when compromised or retired, and associated private keys must be protected. Without lifecycle automation, expired certificates and unmanaged keys can cause outages or security failures. Cryptographic strength alone is insufficient if certificate operations and key custody are poorly designed.<\/span><\/p>\n<p><b>Question 207.<\/b><\/p>\n<p><b>A security architect wants to ensure that software dependencies from external repositories are trustworthy before they enter the build pipeline. Which control BEST supports this goal?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable build logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit developers to download arbitrary packages directly into production<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use approved repositories, dependency verification, and software-supply-chain controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share signing keys with all developers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use approved repositories, dependency verification, and software-supply-chain controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party dependencies can introduce malicious code, vulnerable libraries, or tampered packages. Approved repositories, integrity verification, dependency inventories, vulnerability checks, and controlled build processes help reduce software-supply-chain risk. Signing and provenance mechanisms can provide additional assurance. Allowing unrestricted package downloads or exposing signing keys would weaken rather than strengthen the integrity of the development process.<\/span><\/p>\n<p><b>Question 208.<\/b><\/p>\n<p><b>A business requires an application to remain available after failure of an entire primary site. Which architecture provides the BEST protection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Two servers in the same rack<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A larger uninterruptible power supply at the primary site<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Additional local disk capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A geographically separate recovery or active service capability with tested failover**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A geographically separate recovery or active service capability with tested failover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Site-level failures can affect power, network connectivity, cooling, physical infrastructure, and all systems within the location. Geographic separation reduces common-mode failure risk. The secondary capability should include the processing, data, networking, and security services needed to meet business RTO and RPO targets. Failover must be tested because untested redundancy may not function correctly during a real disaster.<\/span><\/p>\n<p><b>Question 209.<\/b><\/p>\n<p><b>Why should encryption keys for highly sensitive applications be separated from the encrypted application data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separation reduces the likelihood that compromise of the data store also exposes the decryption keys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It removes the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that cryptography cannot fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It eliminates key rotation requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Separation reduces the likelihood that compromise of the data store also exposes the decryption keys<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption provides limited protection if keys are stored beside the encrypted data with equivalent access controls. Separating key storage through a dedicated key-management system or hardware security mechanism can reduce the chance that one compromise exposes both data and keys. Key lifecycle management, access restrictions, auditing, rotation, and recovery are still necessary. Separation is one element of a broader cryptographic architecture.<\/span><\/p>\n<p><b>Question 210.<\/b><\/p>\n<p><b>A company wants to grant access based on user role, device health, network context, and transaction risk. Which approach is MOST suitable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared-account authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attribute-based or contextual access control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static network trust only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Attribute-based or contextual access control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based and contextual access control can evaluate multiple characteristics such as user identity, role, device compliance, location, resource sensitivity, time, and transaction risk. This allows more granular and adaptive decisions than a simple static role or network location. Policies should remain manageable and auditable, and access should still follow least-privilege principles.<\/span><\/p>\n<p><b>Question 211.<\/b><\/p>\n<p><b>An architect discovers that a critical application can modify its own audit logs. What is the PRIMARY security concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Log files may consume too much storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The application may use too much processor capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evidence of malicious or unauthorized actions could be altered or destroyed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Users may receive too many alerts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Evidence of malicious or unauthorized actions could be altered or destroyed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit records support accountability, incident response, and forensic investigation. If the application or an attacker controlling it can freely alter the only audit evidence, malicious activity may be concealed. Critical logs should therefore be forwarded to or protected by an independent logging mechanism with restricted modification rights. Integrity protection and appropriate retention further strengthen trust in audit records.<\/span><\/p>\n<p><b>Question 212.<\/b><\/p>\n<p><b>A system is required to process highly confidential information but must also remain accessible during an authorization-service outage. What should the architect do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Always fail open<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable authorization permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted access to maintain availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Define an explicit risk-based continuity design that preserves fail-secure behavior for sensitive operations**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Define an explicit risk-based continuity design that preserves fail-secure behavior for sensitive operations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security and availability requirements can conflict during dependency failures. The architecture should define which operations may use cached decisions, how long those decisions remain valid, and which sensitive operations must stop if authorization cannot be verified. A blanket fail-open approach is inappropriate for highly confidential data. The decision should be based on business impact, risk tolerance, and the sensitivity of each function.<\/span><\/p>\n<p><b>Question 213.<\/b><\/p>\n<p><b>Which activity MOST directly helps identify whether a proposed architecture contains unnecessary trust relationships?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat modeling and trust-boundary analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Increasing server memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reviewing user-interface colors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Counting application source files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Threat modeling and trust-boundary analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat modeling and trust-boundary analysis help architects understand how users, systems, services, and external parties interact and where trust is assumed. This can reveal relationships that are broader than necessary, such as unrestricted internal access or implicit trust between application components. Unnecessary trust should be reduced through authentication, segmentation, authorization, and explicit policy enforcement.<\/span><\/p>\n<p><b>Question 214.<\/b><\/p>\n<p><b>A security architect is designing backup protection for a ransomware-resilient environment. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow production administrators unrestricted deletion of all backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Maintain isolated or immutable recovery copies with separately controlled access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep one writable backup attached to every production server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable backup verification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Maintain isolated or immutable recovery copies with separately controlled access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware can target both production data and accessible backups. Isolated, offline, or immutable recovery copies reduce the chance that a compromised production account can encrypt or delete all recovery data. Access to backups should be separately controlled and monitored, and restoration procedures should be tested. Backup security should account for malicious administrative compromise, not only hardware failure or accidental deletion.<\/span><\/p>\n<p><b>Question 215.<\/b><\/p>\n<p><b>An application processes sensitive data but retains it indefinitely even after the business purpose has ended. Which principle is being violated MOST directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Complete mediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Defense in depth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data minimization and appropriate retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data minimization and appropriate retention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitive information should not be retained longer than necessary for legitimate business, legal, or regulatory purposes. Excessive retention increases privacy exposure, storage risk, and breach impact. An appropriate architecture should include retention schedules, secure deletion, and lifecycle controls. Data minimization applies not only to collection but also to continued storage of information after its original purpose has ended.<\/span><\/p>\n<p><b>Question 216.<\/b><\/p>\n<p><b>A business wants to use one identity provider across hundreds of applications. What should the architect address MOST carefully?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The provider&#8217;s interface design<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The number of application icons<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Employee office assignments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Concentration risk, resilience, strong administration, and recovery of the identity service**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Concentration risk, resilience, strong administration, and recovery of the identity service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A centralized identity provider can simplify authentication and policy enforcement, but it also becomes a highly critical dependency. An outage or compromise could affect hundreds of applications simultaneously. The architecture should therefore address redundancy, secure administration, privileged-access controls, monitoring, disaster recovery, key protection, and tested failover. Shared security services require especially strong resilience and governance.<\/span><\/p>\n<p><b>Question 217.<\/b><\/p>\n<p><b>A security architect wants to reduce the likelihood that unauthorized software reaches production. What should be implemented?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A controlled build and deployment process with approvals, integrity checks, and traceable artifacts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Direct developer modification of production systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared production administrator credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabled deployment logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A controlled build and deployment process with approvals, integrity checks, and traceable artifacts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure build and deployment process provides consistent controls over what reaches production. Code review, testing, artifact integrity verification, approvals, and traceability help prevent unreviewed or tampered software from being deployed. Direct production changes should be minimized. The pipeline itself is sensitive infrastructure and should be protected with strong access controls and monitoring.<\/span><\/p>\n<p><b>Question 218.<\/b><\/p>\n<p><b>Which control BEST supports nonrepudiation for digitally signed high-value transactions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared signing keys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Strong signer identity, protected private keys, trusted timestamps, and verifiable signatures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous transaction submission<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabled transaction logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Strong signer identity, protected private keys, trusted timestamps, and verifiable signatures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Nonrepudiation depends on reliable evidence linking an action to a specific party. Strong identity assurance, controlled private-key custody, digital signatures, timestamps, and protected audit evidence strengthen that linkage. Shared keys undermine attribution because several users could perform the same signing action. The architecture must protect both the cryptographic keys and the evidence used to verify transactions.<\/span><\/p>\n<p><b>Question 219.<\/b><\/p>\n<p><b>A legacy system cannot support the organization&#8217;s required authentication standard. What should the security architect do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all security controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Grant unrestricted access because the system is legacy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the resulting risk and identify compensating controls or a remediation path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hide the system from architecture documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the resulting risk and identify compensating controls or a remediation path<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legacy constraints should be handled through formal risk management. The architect should determine how much risk the authentication limitation creates and whether controls such as network isolation, access gateways, stronger upstream authentication, monitoring, or restricted privileges can compensate. A long-term modernization or replacement plan may also be necessary. Ignoring the limitation creates unmanaged technical and security debt.<\/span><\/p>\n<p><b>Question 220.<\/b><\/p>\n<p><b>Which approach BEST supports long-term effectiveness of an ISSAP-level enterprise security architecture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review architecture only after major breaches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow permanent undocumented exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Freeze all security standards indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Continuously reassess requirements, risks, dependencies, exceptions, and control effectiveness**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Continuously reassess requirements, risks, dependencies, exceptions, and control effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise security architecture must adapt as business priorities, threats, technologies, regulations, and external dependencies change. Mature practice includes ongoing architecture reviews, documented exceptions, risk tracking, control validation, and reassessment of assumptions. A design that was appropriate several years ago may no longer address current risk. Continuous governance keeps architecture aligned with the organization&#8217;s evolving environment.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 201. A security architect is designing a new enterprise application that will process confidential data across several business units. What should be established FIRST? Security requirements derived from business objectives, data sensitivity, and risk 2. The preferred firewall vendor 3. The final penetration-testing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19077"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19077"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19077\/revisions"}],"predecessor-version":[{"id":19078,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19077\/revisions\/19078"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}