{"id":19081,"date":"2026-09-22T11:33:00","date_gmt":"2026-09-22T11:33:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19081"},"modified":"2026-09-22T11:33:00","modified_gmt":"2026-09-22T11:33:00","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 241.<\/b><\/p>\n<p><b>A security architect is designing a new federated identity solution between two enterprises. What should be established FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The trust model, identity assurance requirements, and allowed claims<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The user-interface theme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of help-desk staff<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The physical location of every identity server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The trust model, identity assurance requirements, and allowed claims<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federation depends on clearly defined trust between identity providers and relying parties. The architect should determine what level of authentication assurance is required, which identity attributes may be exchanged, how assertions are validated, and how authorization decisions will use those claims. Key or certificate management, monitoring, and trust termination procedures should follow from this model. Cosmetic and staffing factors do not establish secure federation.<\/span><\/p>\n<p><b>Question 242.<\/b><\/p>\n<p><b>A highly sensitive application uses several cryptographic keys for different functions. Which design BEST limits the impact of one key being compromised?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use the same key for encryption, signing, and authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Separate keys by purpose and scope, and manage their lifecycles independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store every key in application source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Never rotate any key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Separate keys by purpose and scope, and manage their lifecycles independently<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic keys should generally be separated according to purpose, system, and security domain. If one narrowly scoped key is compromised, other cryptographic functions can remain protected. Independent rotation and revocation also become easier. Using a single key for many purposes increases the blast radius of compromise and can weaken accountability. Strong key management includes generation, storage, access control, rotation, recovery, revocation, and destruction.<\/span><\/p>\n<p><b>Question 243.<\/b><\/p>\n<p><b>A security architect wants to identify whether a planned application redesign introduces new trust boundaries. Which activity is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware-capacity testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> License counting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Updating data-flow and trust-boundary diagrams<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Changing server naming conventions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Updating data-flow and trust-boundary diagrams<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Architecture changes can alter where information crosses between networks, applications, users, external services, or administrative domains. Updated data-flow and trust-boundary diagrams help the architect identify these transitions and determine whether new authentication, authorization, validation, encryption, or monitoring controls are required. Capacity and licensing reviews do not reveal changes in security trust assumptions.<\/span><\/p>\n<p><b>Question 244.<\/b><\/p>\n<p><b>An enterprise uses a single privileged-access gateway for every production environment. What is the PRIMARY architectural concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The gateway may use strong authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Administrators may need training<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The gateway may create detailed logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It may become a critical concentration point and single point of failure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It may become a critical concentration point and single point of failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized privileged-access gateways can strengthen security, but they also become important shared dependencies. Failure may prevent administrators from reaching production systems, while compromise may expose many environments. The architecture should therefore include strong hardening, monitoring, redundancy, secure recovery, and carefully controlled administration. Centralization creates value only when concentration risk is explicitly managed.<\/span><\/p>\n<p><b>Question 245.<\/b><\/p>\n<p><b>Which approach BEST reduces privilege accumulation when employees frequently change roles?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Periodically review access and remove permissions no longer required<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow users to retain all previous access indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give every user administrator rights<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable identity governance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Periodically review access and remove permissions no longer required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role changes can cause users to accumulate permissions from previous responsibilities. Regular access reviews and timely deprovisioning help enforce least privilege throughout the identity lifecycle. Access should be adjusted when employees transfer, change duties, or leave the organization. Retaining unnecessary privileges increases the impact of credential compromise and insider misuse.<\/span><\/p>\n<p><b>Question 246.<\/b><\/p>\n<p><b>A security architect is evaluating whether an application can rely on cached authorization decisions during a temporary outage. What should drive the decision MOST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The application&#8217;s color scheme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Resource sensitivity, cache age, business impact, and risk tolerance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of developers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Server rack location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Resource sensitivity, cache age, business impact, and risk tolerance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cached authorization can improve availability but may use stale permissions after access has been revoked or changed. The architect should determine which operations may safely rely on cached decisions, how long those decisions remain acceptable, and when the application must fail secure. Highly sensitive functions may require current authorization, while lower-risk operations may tolerate limited caching under controlled conditions.<\/span><\/p>\n<p><b>Question 247.<\/b><\/p>\n<p><b>A production application depends on an open-source library that is no longer maintained. What should the security architect do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the issue because the application currently works<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable vulnerability monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the dependency risk and establish replacement, mitigation, or containment measures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Publish the library directly to the internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the dependency risk and establish replacement, mitigation, or containment measures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unsupported software can accumulate unpatched vulnerabilities and create long-term supply-chain risk. The architect should evaluate the application&#8217;s dependency on the library, exposure, compensating controls, and available alternatives. Replacement or modernization may be the preferred long-term solution, while interim isolation or monitoring can reduce risk. Unsupported dependencies should be visible in risk and lifecycle management.<\/span><\/p>\n<p><b>Question 248.<\/b><\/p>\n<p><b>A critical database is replicated to a secondary region, but both regions depend on the same external network provider. What risk remains?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Database encryption may be too strong<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replication may create audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Secondary storage may be larger<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A common network-provider failure could affect both regions**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A common network-provider failure could affect both regions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic redundancy does not eliminate common-mode failures when supposedly independent environments share critical underlying dependencies. If both regions rely on one network provider, an outage at that provider could defeat the resilience design. Architects should map shared dependencies and, where justified, diversify network routes, providers, DNS, identity, and other critical services to achieve genuine independence.<\/span><\/p>\n<p><b>Question 249.<\/b><\/p>\n<p><b>What is the PRIMARY security benefit of using individual administrator accounts rather than a shared privileged account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Actions can be attributed to specific administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Passwords never need to change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Authorization is no longer necessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitoring can be disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Actions can be attributed to specific administrators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Individual privileged identities improve accountability because actions can be tied to specific administrators. They also allow permissions to be assigned, revoked, and monitored independently. Shared accounts obscure responsibility and make investigations more difficult. Strong authentication, session controls, and protected audit logging should complement unique identities for sensitive administrative access.<\/span><\/p>\n<p><b>Question 250.<\/b><\/p>\n<p><b>A business wants to expose selected internal services to partners without giving partners broad network access. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Extend the internal network directly to every partner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use a controlled gateway or API layer with explicit authentication and authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable partner authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Place internal databases directly on the internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use a controlled gateway or API layer with explicit authentication and authorization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A controlled gateway creates a defined boundary between partners and internal systems. It can enforce authentication, authorization, request validation, rate limiting, encryption, and logging while exposing only approved services. Extending broad internal network access unnecessarily increases trust and attack surface. Partner access should be limited to the precise functions and data required for the business relationship.<\/span><\/p>\n<p><b>Question 251.<\/b><\/p>\n<p><b>A security architect finds that a service can modify its own security policy configuration. What is the MAIN concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The service may generate too many alerts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Performance may improve<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compromise of the service could allow it to weaken its own controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy files may use too much storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Compromise of the service could allow it to weaken its own controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security mechanisms should be protected from the components they govern when practical. If a compromised service can modify its own authorization rules, logging settings, or other security policy, an attacker may disable controls and conceal activity. Policy administration should be restricted to trusted management paths, protected identities, and controlled change processes. Separation improves integrity of the enforcement environment.<\/span><\/p>\n<p><b>Question 252.<\/b><\/p>\n<p><b>A service must remain available during maintenance of one server. Which architecture BEST supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shut down the entire service during maintenance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store backups only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one very large server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Deploy redundant nodes so traffic can continue through healthy components**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Deploy redundant nodes so traffic can continue through healthy components<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Redundant nodes allow planned maintenance or individual server failure without taking the entire service offline. Load balancing, session management, data consistency, and failover behavior should be designed and tested according to availability requirements. Backups support recovery but do not provide immediate service continuity. Redundancy should also avoid hidden shared failure points.<\/span><\/p>\n<p><b>Question 253.<\/b><\/p>\n<p><b>Which practice BEST helps prevent sensitive information from remaining indefinitely in temporary processing locations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Define retention and secure-deletion requirements for temporary data stores<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep all temporary files permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable data classification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow users to choose retention informally<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Define retention and secure-deletion requirements for temporary data stores<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Temporary files, caches, staging databases, and processing queues can contain sensitive information even when they are not considered primary data stores. Architecture should define how long such information may remain and how it is securely removed when no longer required. This supports data minimization and reduces the number of locations where sensitive data can be exposed.<\/span><\/p>\n<p><b>Question 254.<\/b><\/p>\n<p><b>An organization wants to prevent unauthorized devices from connecting to a sensitive administrative network. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust every device on the internal network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require device authentication and posture validation before access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable network access controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use only a shared Wi-Fi password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Require device authentication and posture validation before access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitive networks should validate both the user and the device where appropriate. Device certificates, managed-device status, endpoint security posture, and other controls can help ensure that only approved systems reach administrative resources. A shared password or internal network location alone provides weak assurance and may allow compromised or unmanaged devices to access privileged paths.<\/span><\/p>\n<p><b>Question 255.<\/b><\/p>\n<p><b>A security architect is evaluating a proposed direct connection between a public web server and a highly sensitive database. What is the BEST response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve it because the web server needs data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable database authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Introduce a controlled application tier and restrict database access to required flows<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Place the database on the public internet<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Introduce a controlled application tier and restrict database access to required flows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Direct access from an internet-facing system to a sensitive database increases risk. A layered architecture can separate the public web tier from application logic and the data tier, allowing the organization to enforce controls at each boundary. Database communication should be limited to approved application identities and required protocols. This supports segmentation and defense in depth.<\/span><\/p>\n<p><b>Question 256.<\/b><\/p>\n<p><b>A security architect is considering a permanent exception to a security standard because remediation is expensive. What should be done?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve the exception without documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the system from the asset inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Document the risk, compensating controls, owner, approval, and review or expiration date**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Document the risk, compensating controls, owner, approval, and review or expiration date<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security exceptions should not become unmanaged permanent weaknesses. The organization should understand the residual risk, document why the standard cannot currently be met, identify compensating controls, assign an accountable owner, and establish periodic review or expiration. Cost can influence risk decisions, but it does not eliminate the need for formal governance and accountability.<\/span><\/p>\n<p><b>Question 257.<\/b><\/p>\n<p><b>What is the MAIN architectural value of identifying shared dependencies across multiple applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It reveals concentration risk and potential cascading impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for backup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It prevents every outage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It guarantees applications are secure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It reveals concentration risk and potential cascading impact<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Several applications may depend on the same identity platform, DNS service, network provider, key manager, database, or external SaaS provider. Identifying these shared dependencies allows architects to understand how one failure or compromise might affect many services. This information supports resilience planning, risk prioritization, incident response, and investment decisions.<\/span><\/p>\n<p><b>Question 258.<\/b><\/p>\n<p><b>A secure development pipeline uses digital signatures on deployment artifacts. What should be protected MOST carefully?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Developer desktop wallpapers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The private signing keys and signing process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The names of build servers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Public verification keys from authorized disclosure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The private signing keys and signing process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If an attacker obtains the private signing key or compromises the signing process, malicious software may appear legitimate because it carries a valid signature. Private keys should therefore be strongly protected, access should be limited, signing actions should be audited, and revocation procedures should exist. Public verification keys are intended to be distributed to systems that validate signatures.<\/span><\/p>\n<p><b>Question 259.<\/b><\/p>\n<p><b>A legacy system cannot support centralized logging. What should the security architect do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume logging is unnecessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all local logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the monitoring gap and implement feasible compensating collection or oversight controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Exclude the system from incident response<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the monitoring gap and implement feasible compensating collection or oversight controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A legacy limitation should trigger risk analysis rather than abandonment of the requirement. Depending on technical constraints, compensating controls might include log forwarding through an intermediary, network monitoring, local log collection with restricted access, or additional detection around the system. The residual gap should be documented, and modernization may be appropriate if the risk remains unacceptable.<\/span><\/p>\n<p><b>Question 260.<\/b><\/p>\n<p><b>Which practice BEST supports a mature security architecture program as the enterprise evolves?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat architecture decisions as permanent<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow undocumented exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reassess only after security incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Continuously review risks, dependencies, standards, exceptions, and changing business requirements**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Continuously review risks, dependencies, standards, exceptions, and changing business requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture must remain aligned with an environment that continually changes. New technologies, acquisitions, regulatory requirements, threats, and business processes can invalidate earlier assumptions. Mature programs therefore maintain architecture standards, track exceptions, reassess shared dependencies and risks, and update designs when conditions materially change. Continuous governance keeps architecture relevant and defensible over time.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 241. A security architect is designing a new federated identity solution between two enterprises. What should be established FIRST? The trust model, identity assurance requirements, and allowed claims 2. The user-interface theme 3. The number of help-desk staff 4. The physical location of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19081"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19081"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19081\/revisions"}],"predecessor-version":[{"id":19082,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19081\/revisions\/19082"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}