{"id":19091,"date":"2026-09-22T11:34:24","date_gmt":"2026-09-22T11:34:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=19091"},"modified":"2026-09-22T11:34:24","modified_gmt":"2026-09-22T11:34:24","slug":"isc-cissp-issap-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isc-cissp-issap-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"ISC CISSP-ISSAP Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cissp-issap-exam-dumps\"><b>ISC CISSP-ISSAP Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 341.<\/b><\/p>\n<p><b>A security architect is designing a new multi-tenant application. Which architectural concern should be addressed MOST carefully?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Tenant isolation and prevention of unauthorized cross-tenant access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The color scheme selected by each tenant<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of developers assigned to the project<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The physical size of the database servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Tenant isolation and prevention of unauthorized cross-tenant access<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multi-tenant systems must ensure that one tenant cannot access another tenant&#8217;s data, identities, or administrative functions. Strong logical isolation, authorization, data partitioning, encryption, and monitoring may all contribute to this objective. The architect should also examine shared infrastructure and management planes for cross-tenant attack paths. Cosmetic and staffing factors do not address the central security risk created by shared application infrastructure.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>An organization wants to reduce exposure from long-lived cloud API credentials. Which design is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store permanent keys in source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use short-lived credentials issued through workload identity mechanisms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one API key across all applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable API authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use short-lived credentials issued through workload identity mechanisms<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived credentials reduce the useful lifetime of stolen authentication material and can eliminate the need to distribute permanent secrets to applications. Workload identity mechanisms can issue credentials dynamically based on an authenticated service identity. The resulting permissions should still be narrowly scoped according to least privilege. Long-lived shared keys create greater exposure and are more difficult to rotate safely.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>A security architect wants to understand how compromise of a shared message broker could affect the enterprise. Which activity is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing interface colors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Counting broker administrator accounts only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mapping application dependencies on the shared broker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increasing broker storage capacity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Mapping application dependencies on the shared broker<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency mapping shows which business applications rely on the message broker and helps the architect understand potential cascading impact from failure or compromise. Shared middleware can create concentration risk even when individual applications appear independently resilient. Understanding dependencies supports resilience planning, segmentation, access control, incident response, and prioritization of security investment.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>A highly sensitive application depends on a centralized authorization service. Which design is MOST appropriate if the authorization service becomes unavailable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically grant all requested access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit administrator access without verification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication temporarily<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Follow predefined fail-secure behavior for sensitive operations**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Follow predefined fail-secure behavior for sensitive operations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization-service failure should not become an automatic path to unauthorized access. For sensitive operations, the safest design normally denies access until policy can be verified. Carefully controlled cached authorization may be acceptable for selected lower-risk functions, but this behavior must be explicitly designed. The architecture should balance availability requirements with the confidentiality and integrity impact of stale or unavailable authorization.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>Why should security architects identify where administrative privileges are permanently assigned?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Standing privilege increases the window in which compromised accounts can be abused<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent privileges always improve productivity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Standing privilege eliminates the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Privileged accounts cannot be compromised<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Standing privilege increases the window in which compromised accounts can be abused<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Permanent privileged access remains available even when the administrator is not actively performing sensitive work. This creates a larger opportunity for attackers who compromise the account. Just-in-time privilege, approval workflows, dedicated administrative identities, and automatic expiration can reduce this exposure. Privileged access should be assigned only when required and monitored closely.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>An enterprise is designing an encrypted data archive that must be retained for many years. Which cryptographic concern is MOST important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The graphical design of the archive interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Long-term key lifecycle, algorithm suitability, and recoverability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The number of archive administrators only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the archive uses compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Long-term key lifecycle, algorithm suitability, and recoverability<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Long-term archives may outlive individual encryption keys, cryptographic algorithms, products, and administrators. The architecture should therefore address secure key retention, escrow or recovery where appropriate, rotation, migration to stronger algorithms, and destruction when retention ends. Data that remains encrypted but whose keys are lost may become permanently unavailable, while obsolete algorithms may eventually provide insufficient protection.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>A development team wants direct administrative access to production databases for troubleshooting. What is the BEST architectural response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant permanent administrator access to all developers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Share the database administrator password<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Provide controlled, time-limited privileged access with auditing when justified<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable database logging during troubleshooting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Provide controlled, time-limited privileged access with auditing when justified<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Troubleshooting may occasionally require privileged production access, but that does not justify permanent broad permissions. A controlled process can grant temporary access after appropriate approval and strong authentication, then remove it automatically. Detailed logging or session monitoring supports accountability. This balances operational needs with least privilege and separation between development and production environments.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>A company operates two disaster-recovery sites, but both depend on the same cloud-based DNS provider. What should the architect recognize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cannot affect disaster recovery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The sites are fully independent because they are geographically separated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The provider automatically guarantees availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The shared DNS dependency creates a common-mode failure risk**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The shared DNS dependency creates a common-mode failure risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographically separate sites may still fail together if they depend on the same critical external service. A DNS-provider outage or compromise could prevent users or systems from reaching either recovery site. Architects should evaluate shared dependencies such as DNS, network carriers, identity providers, certificate services, and cloud control planes when determining whether redundancy is genuinely independent.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>Which approach BEST protects sensitive administrative actions performed through a web management console?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Strong authentication, restricted network access, session controls, and protected audit logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Anonymous access from the corporate network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A hidden URL with no additional controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shared administrator credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Strong authentication, restricted network access, session controls, and protected audit logging<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Administrative consoles are high-value targets because they can provide extensive control over systems and data. Strong authentication, limited reachability, session protection, authorization, and independent logging reduce exposure and improve accountability. A hidden URL is not a meaningful security control, while shared credentials make it difficult to attribute administrative actions to a specific person.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>An organization wants to ensure that authorization policies are applied consistently across many applications. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Let every application define unrelated access rules with no governance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establish centralized policy governance with consistent enforcement mechanisms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove authorization from internal applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use network location as the only access criterion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Establish centralized policy governance with consistent enforcement mechanisms<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized policy governance can promote consistent access decisions, reduce duplicated logic, and simplify updates across applications. Enforcement may occur centrally or through distributed policy enforcement points, but rules should be governed consistently. Availability and performance requirements must also be considered so the policy architecture does not create an unacceptable single point of failure.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>A security architect discovers that production containers are built from unverified public images. What is the MAIN risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The images may be larger than necessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Developers may use different naming conventions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Malicious or vulnerable components may enter the production supply chain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Container logs may increase<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Malicious or vulnerable components may enter the production supply chain<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unverified container images can contain known vulnerabilities, malicious software, outdated dependencies, or unauthorized modifications. Secure architecture should use approved registries, signed or integrity-verified images, vulnerability scanning, provenance information, and controlled build processes. Trust should be established through verifiable controls rather than assuming that an image is safe because it is publicly available.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>A business requires a critical system to recover within two hours and tolerate no more than ten minutes of data loss. Which statement is correct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RTO is ten minutes and RPO is two hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Both RTO and RPO are two hours<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Both RTO and RPO are ten minutes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> RTO is two hours and RPO is ten minutes**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. RTO is two hours and RPO is ten minutes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective defines how quickly the system must be restored, so the RTO is two hours. The recovery point objective defines the maximum acceptable data loss measured in time, so the RPO is ten minutes. These requirements influence standby capacity, automation, replication, backup frequency, and recovery procedures. Both should be validated through realistic recovery testing.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>What is the PRIMARY reason to protect architecture diagrams that show internal trust boundaries and privileged management paths?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They may reveal sensitive information useful for planning attacks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Diagrams cannot be shared with administrators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Security architecture should always remain secret to function<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Diagrams replace access controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. They may reveal sensitive information useful for planning attacks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Architecture diagrams can contain detailed information about management networks, trust relationships, critical systems, and security controls. They should therefore be classified and shared according to legitimate need. However, the security of the architecture should not depend solely on keeping the design secret. Strong controls must remain effective even if an attacker learns significant details about the system.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>A security architect is designing workload access to a cloud database. Which control BEST supports least privilege?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every workload the database administrator role<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Grant each workload only the specific database permissions it requires<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable database authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one unrestricted service account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Grant each workload only the specific database permissions it requires<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload permissions should correspond to legitimate application functions. A reporting service may need read access, while a transaction service may require limited write operations. Giving every workload administrator rights unnecessarily increases the impact of compromise. Separate identities and narrowly scoped permissions also improve accountability and make access easier to revoke or modify independently.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>A security architect learns that a critical third-party provider can terminate service with little notice. What is the MOST important response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the contractual risk because the provider is reputable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Increase internal server capacity only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Develop an exit strategy, data-portability plan, and alternative business process<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable third-party monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Develop an exit strategy, data-portability plan, and alternative business process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party dependency risk includes more than security incidents and outages. Provider termination, financial failure, strategic change, or contract disputes can also disrupt operations. An exit strategy should address data retrieval, migration, replacement services, authentication dependencies, and continuity procedures. Planning before a crisis reduces concentration risk and supports business resilience.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>An organization uses cached credentials to maintain service during an identity outage. What is the PRIMARY security risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cached credentials always improve confidentiality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Caching eliminates the need for identity management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cached data cannot be compromised<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Revoked or changed access may remain usable until the cache expires**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Revoked or changed access may remain usable until the cache expires<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential or authorization caching can improve availability, but it creates a window in which stale access decisions remain effective. If an account is disabled or permissions are revoked, a disconnected system may continue allowing access based on cached information. The architecture should define cache lifetime, invalidation behavior, protected storage, and which operations require current verification.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>Why should a security architect document assumptions behind a major architecture decision?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assumptions can later be reassessed when business or technical conditions change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assumptions never change once documented<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Documentation eliminates future architecture reviews<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assumptions replace security requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assumptions can later be reassessed when business or technical conditions change<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Architecture decisions often depend on assumptions about threats, data sensitivity, availability, technology, cost, and external services. Over time, those assumptions may no longer be valid. Documenting them makes future reassessment easier and helps new architects understand why a design was chosen. Decision records support lifecycle governance rather than freezing architecture permanently.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>A security architect wants to reduce the risk of unauthorized changes to cloud infrastructure. Which approach is BEST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit direct console changes by all developers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use controlled infrastructure-as-code deployment with review, integrity, and audit controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable cloud audit logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one administrator account across teams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use controlled infrastructure-as-code deployment with review, integrity, and audit controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure as code can make cloud configuration changes repeatable, reviewable, and traceable. A controlled pipeline can enforce peer review, testing, approval, and integrity checks before deployment. Direct console changes should be restricted or reconciled to prevent configuration drift. The pipeline and its credentials are themselves critical security assets and should be strongly protected.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>A high-value transaction system requires evidence that an approved transaction was not altered after authorization. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Increased storage redundancy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cryptographic integrity protection and protected transaction audit records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Anonymous transaction submission<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Cryptographic integrity protection and protected transaction audit records<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity controls help detect unauthorized modification of transaction data after approval. Digital signatures, message authentication codes, or comparable cryptographic mechanisms can protect transaction contents, while protected audit records provide evidence of the approval and processing sequence. Identity assurance and key protection are also important when signatures are used to establish accountability or nonrepudiation.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>Which practice BEST reflects mature enterprise security architecture governance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approve designs once and never revisit them<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow undocumented security exceptions indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review architecture only after major incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Continuously govern architecture decisions, dependencies, standards, risks, exceptions, and control effectiveness**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Continuously govern architecture decisions, dependencies, standards, risks, exceptions, and control effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise security architecture must evolve with changing threats, regulations, business priorities, technologies, and dependencies. Mature governance maintains principles and standards, records important decisions, manages exceptions, tracks residual risk, and reassesses control effectiveness. Continuous review prevents outdated assumptions or temporary exceptions from becoming permanent weaknesses and keeps the architecture aligned with current organizational needs.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ISC CISSP-ISSAP Exam Dumps and Practice Test Dumps &nbsp; Question 341. A security architect is designing a new multi-tenant application. Which architectural concern should be addressed MOST carefully? Tenant isolation and prevention of unauthorized cross-tenant access 2. The color scheme selected by each tenant 3. The number of developers assigned to the project [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19091"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=19091"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19091\/revisions"}],"predecessor-version":[{"id":19092,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/19091\/revisions\/19092"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=19091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=19091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=19091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}