{"id":19085,"date":"2026-09-22T11:33:32","date_gmt":"2026-09-22T11:33:32","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19085"},"modified":"2026-09-22T11:33:32","modified_gmt":"2026-09-22T11:33:32","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 281.<\/b><\/p>\n<p><b>A security architect is designing access to a highly sensitive analytics platform. Which approach BEST reduces standing administrative privilege?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Just-in-time privileged access with approval, strong authentication, and automatic expiration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent global administrator rights for all support staff<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared administrator accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Unrestricted access from any managed workstation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Just-in-time privileged access with approval, strong authentication, and automatic expiration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time access limits privileged permissions to the period in which they are actually needed. Requiring approval and strong authentication adds further assurance, while automatic expiration prevents privileges from remaining active indefinitely. Permanent administrative assignments increase the attack surface and the consequences of credential compromise. Shared accounts also weaken accountability because actions cannot be reliably attributed to a specific administrator.<\/span><\/p>\n<p><b>Question 282.<\/b><\/p>\n<p><b>A business application relies on a centralized identity provider. Which design BEST reduces the availability risk created by this dependency?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication during outages<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Implement resilient identity services with tested failover and defined degraded-mode behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow permanent anonymous access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store user passwords inside every application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Implement resilient identity services with tested failover and defined degraded-mode behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A centralized identity provider can become a critical shared dependency for many applications. Redundant components and tested failover reduce the risk of authentication outages, while clearly defined degraded-mode behavior ensures applications respond predictably if the service becomes unavailable. Bypassing authentication during failures would introduce serious risk. Resilience should preserve appropriate security rather than trading away identity verification.<\/span><\/p>\n<p><b>Question 283.<\/b><\/p>\n<p><b>A security architect is reviewing an internal API that trusts every request from the corporate network. What is the MAIN concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> API responses may be too large<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The API may generate too many logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network location is being treated as sufficient proof of trust<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Developers may need additional training<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Network location is being treated as sufficient proof of trust<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internal networks can be compromised through phishing, malware, stolen credentials, or vulnerable systems. Trusting requests solely because they originate from an internal network creates excessive implicit trust. A stronger design verifies identity, authorization, and other relevant context for each request. This aligns with Zero Trust principles and reduces the risk that an attacker who reaches the internal network gains broad access automatically.<\/span><\/p>\n<p><b>Question 284.<\/b><\/p>\n<p><b>A critical application uses one hardware security module for every cryptographic function. What is the PRIMARY architectural risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The HSM may create too many audit records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Administrators may need specialized training<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cryptographic operations may consume processor resources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The HSM may become a single point of failure**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The HSM may become a single point of failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If authentication, signing, encryption, or key management all depend on one HSM, failure of that device could affect multiple critical functions. The architecture should consider secure redundancy, protected key synchronization, backup, and tested failover. Availability improvements must preserve the confidentiality and integrity of key material. A resilient design should avoid compromising cryptographic security merely to provide redundancy.<\/span><\/p>\n<p><b>Question 285.<\/b><\/p>\n<p><b>Which security architecture principle BEST supports removing unnecessary services and interfaces from a system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Minimize attack surface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Maximum privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Default allow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Open access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Minimize attack surface<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Every unnecessary service, port, interface, account, and feature creates another potential attack path. Removing or disabling functionality that is not required reduces opportunities for exploitation and simplifies security monitoring. Required services should still be configured securely and restricted to authorized users and systems. Attack-surface reduction is a foundational hardening and architecture principle.<\/span><\/p>\n<p><b>Question 286.<\/b><\/p>\n<p><b>An organization is implementing federation with an external partner. What should be defined MOST clearly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The partner&#8217;s office layout<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust scope, assurance requirements, claims, authorization mappings, and trust termination procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of developers at the partner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The graphical appearance of the login page<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Trust scope, assurance requirements, claims, authorization mappings, and trust termination procedures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federation extends identity trust across organizational boundaries. The architecture should define which identities are trusted, what authentication assurance is acceptable, which claims may be exchanged, how claims map to permissions, and how the trust relationship can be revoked. Certificates, keys, monitoring, and incident procedures should also be governed. Ambiguous trust relationships can easily result in excessive or unintended access.<\/span><\/p>\n<p><b>Question 287.<\/b><\/p>\n<p><b>A security architect discovers that software packages are downloaded directly from public repositories during production builds. Which control would BEST reduce supply-chain risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable build logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow developers to use any package source<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use approved repositories with integrity, provenance, and vulnerability verification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store signing keys in the build script<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Use approved repositories with integrity, provenance, and vulnerability verification<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Public software repositories can contain compromised, malicious, or vulnerable packages. Approved internal or controlled repositories can enforce integrity checking, provenance, dependency review, and vulnerability scanning before packages are used in production builds. Software-supply-chain controls should also protect the build pipeline itself. Storing signing keys directly in scripts would introduce another serious weakness.<\/span><\/p>\n<p><b>Question 288.<\/b><\/p>\n<p><b>A business requires a service to remain available after failure of an entire cloud region. Which design BEST meets the requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy multiple instances in one availability zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store backups only in the primary region<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase the number of virtual machines in the same region<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use geographically separate regional capacity with replicated data and tested failover**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use geographically separate regional capacity with replicated data and tested failover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Regional resilience requires infrastructure outside the affected region. Multiple instances within one region may protect against individual server or zone failures but may not survive a regional outage. Multi-region processing, data replication, independent networking, and tested failover can provide stronger resilience. The design should be based on business RTO and RPO requirements and should account for shared dependencies.<\/span><\/p>\n<p><b>Question 289.<\/b><\/p>\n<p><b>Why should highly privileged administrator sessions be recorded or strongly audited?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To improve accountability and support investigation of sensitive actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To allow administrators to share accounts safely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To guarantee no unauthorized action can occur<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To improve accountability and support investigation of sensitive actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged users can make high-impact changes, so their activity should be attributable and reviewable. Session recording or detailed auditing can support investigations, deter misuse, and help verify that administrative actions followed policy. These controls should be protected from tampering. Auditing complements rather than replaces strong authentication, authorization, and separation of duties.<\/span><\/p>\n<p><b>Question 290.<\/b><\/p>\n<p><b>A security architect needs to ensure that only approved devices access a sensitive SaaS application. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Device posture assessment integrated with access policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous access from internal networks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static IP filtering only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Device posture assessment integrated with access policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture checks can determine whether an endpoint is managed, encrypted, patched, protected by endpoint controls, or otherwise compliant with enterprise requirements. Integrating this information with access policy enables conditional authorization based on both user identity and device trust. Static network location alone provides weaker assurance because compromised or unmanaged devices may still connect from approved networks.<\/span><\/p>\n<p><b>Question 291.<\/b><\/p>\n<p><b>A production system accepts configuration updates from an automated management platform. What is MOST important to protect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system&#8217;s screen resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The management platform&#8217;s user-interface theme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Integrity and authentication of management commands and configuration sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of configuration files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Integrity and authentication of management commands and configuration sources<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An automated management platform can make large-scale changes, so compromise of its commands or configuration sources can affect many systems at once. Strong authentication, authorization, integrity verification, protected communication, and logging are essential. The architecture should also restrict who may alter management policies and should provide rollback or recovery options for harmful changes.<\/span><\/p>\n<p><b>Question 292.<\/b><\/p>\n<p><b>A security architect finds that a failover environment has never been tested. What is the MAIN concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Testing might generate audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The environment may use different hardware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Users may be unfamiliar with the secondary site<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The organization does not know whether the recovery design will work when needed**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The organization does not know whether the recovery design will work when needed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Redundant infrastructure provides little assurance if failover has never been exercised. Configuration drift, missing dependencies, access issues, data-replication problems, or procedural gaps may prevent successful recovery. Testing validates both technical capability and operational procedures. Recovery exercises should be designed around defined RTO and RPO requirements and should include critical supporting dependencies.<\/span><\/p>\n<p><b>Question 293.<\/b><\/p>\n<p><b>Which action BEST supports secure retirement of an application that used external API keys and certificates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke credentials, remove trust relationships, address retained data, and update dependent systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave all credentials active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep unused firewall rules for convenience<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop monitoring without changing access**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Revoke credentials, remove trust relationships, address retained data, and update dependent systems<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Decommissioning must include the security artifacts associated with the application. API keys, certificates, service accounts, firewall rules, trust relationships, and stored data should all be reviewed. Unused credentials and network paths can become hidden attack opportunities. The asset inventory and dependent systems should also be updated so that retired applications no longer influence active operations.<\/span><\/p>\n<p><b>Question 294.<\/b><\/p>\n<p><b>A security architect is deciding how frequently to rotate a sensitive cryptographic key. What should drive the decision MOST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The user&#8217;s preferred schedule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Key purpose, exposure risk, cryptoperiod requirements, and operational impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The physical size of the key-management server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Key purpose, exposure risk, cryptoperiod requirements, and operational impact<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key rotation should be based on risk and cryptographic policy rather than an arbitrary schedule. The architect should consider how the key is used, the sensitivity and volume of protected data, likelihood of exposure, regulatory requirements, and the operational complexity of rotation. Different keys may justify different cryptoperiods. Rotation must also be supported by reliable deployment and recovery procedures.<\/span><\/p>\n<p><b>Question 295.<\/b><\/p>\n<p><b>A business wants stronger assurance for wire transfers above a defined amount. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow every authenticated user to approve high-value transfers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable transaction monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require step-up authentication or independent approval for high-risk transactions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use shorter session timeouts only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Require step-up authentication or independent approval for high-risk transactions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High-value transactions justify stronger controls than routine activity. Step-up authentication can require additional proof of identity, while independent approval can apply separation of duties or dual control. These mechanisms reduce the chance that a stolen session or single compromised account can authorize a major transfer. Transaction risk should influence authentication and authorization strength.<\/span><\/p>\n<p><b>Question 296.<\/b><\/p>\n<p><b>A centralized security service is unavailable, but an application has cached policy information. What should determine whether cached policy may be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The color of the application interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The number of active users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The administrator&#8217;s personal preference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data sensitivity, policy age, operation risk, and defined fail-secure requirements**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Data sensitivity, policy age, operation risk, and defined fail-secure requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cached policy may improve availability, but it can become stale after permissions change or are revoked. The architecture should explicitly define how long cached decisions remain valid and which operations may rely on them. Highly sensitive actions may require current authorization and should fail securely if verification is unavailable. Lower-risk operations may tolerate limited cached policy under documented conditions.<\/span><\/p>\n<p><b>Question 297.<\/b><\/p>\n<p><b>What is the MAIN benefit of maintaining accurate architecture dependency diagrams?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They help identify shared services, trust boundaries, cascading risks, and resilience requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They eliminate the need for testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> They guarantee no system will fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> They replace configuration management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. They help identify shared services, trust boundaries, cascading risks, and resilience requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency diagrams show how applications rely on networks, identity systems, databases, DNS, certificate services, key management, and external providers. This helps architects identify concentration risk, hidden single points of failure, and potential cascading impact. Diagrams also support change planning and incident analysis. They should be maintained as the environment evolves so that architectural decisions remain based on current information.<\/span><\/p>\n<p><b>Question 298.<\/b><\/p>\n<p><b>An organization wants to ensure that only authorized software images can run in a sensitive computing environment. Which control is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow arbitrary images if they start successfully<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require signed, approved images and verify integrity before execution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable image inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust any image stored on an internal server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Require signed, approved images and verify integrity before execution<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Image signing and integrity verification provide assurance that workloads originate from an approved build process and have not been tampered with. The architecture should also control who can sign images, protect signing keys, and maintain trusted repositories. Internal storage location alone does not establish software trust. Integrity controls reduce the risk of unauthorized or modified workloads running in sensitive environments.<\/span><\/p>\n<p><b>Question 299.<\/b><\/p>\n<p><b>A security architect discovers that two supposedly independent recovery sites depend on the same DNS provider. What is the MAIN issue?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS may use too much bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The sites may have different IP ranges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The shared DNS provider creates a common-mode failure risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Both sites may generate identical logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The shared DNS provider creates a common-mode failure risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery sites can appear independent while sharing critical external dependencies. If both depend on one DNS provider, a provider outage or compromise may affect both sites simultaneously and defeat the resilience strategy. Architects should identify shared dependencies and determine whether diversification, alternate resolution mechanisms, or other contingency measures are required based on business continuity objectives.<\/span><\/p>\n<p><b>Question 300.<\/b><\/p>\n<p><b>Which approach BEST reflects mature enterprise security architecture practice?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat every approved design as permanent<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit undocumented exceptions indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review architecture only after incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Continuously govern standards, decisions, dependencies, exceptions, risks, and architecture effectiveness**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Continuously govern standards, decisions, dependencies, exceptions, risks, and architecture effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture must adapt as business processes, technologies, regulations, external dependencies, and threats evolve. Mature practice includes maintaining standards, documenting design decisions, governing exceptions, reviewing shared dependencies, tracking residual risk, and measuring whether controls continue to meet requirements. Continuous governance keeps architecture aligned with the organization&#8217;s current risk environment instead of allowing past assumptions to remain unchallenged.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 281. A security architect is designing access to a highly sensitive analytics platform. Which approach BEST reduces standing administrative privilege? Just-in-time privileged access with approval, strong authentication, and automatic expiration 2. Permanent global administrator rights for all support staff 3. Shared administrator accounts [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19085"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19085"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19085\/revisions"}],"predecessor-version":[{"id":19086,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19085\/revisions\/19086"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}