ISSAP Cheat Sheet
Governance, Risk, and Compliance (GRC)
Identify Security Requirements
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Binding authority determines whether guidance is mandatory
A law, regulation, directive, or contract creates an obligation through its governing authority, while a framework or guideline is voluntary unless that authority incorporates it. The architect must establish applicability before treating published guidance as a compliance mandate.
Trap Treat every cited framework as independently mandatory
4 questions test this
- A private water utility's board reads that a federal agency has published cross-sector cybersecurity performance goals and asks whether the utility now has a compliance deadline for meeting them. How
- A federal civilian executive branch agency is told to remediate a named vulnerability class within a fixed deadline, and the instruction applies to it whether or not its own policy already required th
- A retailer's merchant agreement with its acquiring bank incorporates the acquirer's PCI compliance program. The project team nevertheless asserts that PCI DSS binds the company as national law. Which
- An insurer adopted a published cybersecurity framework as internal good practice, and its board now asks whether the firm is legally bound by every outcome that framework states. Which condition would
- ISO/IEC 27001 defines requirements for an information security management system
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS using a risk management process. It is the certifiable management-system standard, not merely a catalog of technical safeguards.
Trap Use ISO/IEC 27002 as the certifiable requirements standard
4 questions test this
- Certification is offered to an organisation against the international code of practice for information security controls, with an accredited certificate promised on completion of a short audit. Which
- A supplier tells a bank that it applies the international code of practice for information security controls and that this makes its management system certifiable. Against which standard's requirement
- A software company plans to select its security controls by copying the control list a larger competitor publishes, and then to claim conformity with the certifiable information security management sy
- The certifiable management system standard requires an information security risk process but does not itself describe how to run one, and a separate international document exists to support exactly th
- The NIST Cybersecurity Framework states outcomes without prescribing implementations
CSF 2.0 supplies a technology-neutral taxonomy of cybersecurity outcomes and points to informative resources for practices and controls. An architect tailors those outcomes to mission, risk appetite, and sector rather than treating the Core as a fixed control baseline.
Trap Implement every CSF outcome through a prescribed NIST technology
4 questions test this
- The four Cybersecurity Framework 2.0 Tiers can be applied to an Organizational Profile, and a higher Tier is often assumed to bring a defined set of additional controls with it. Which characterisation
- An insurer's team proposes to decide which Cybersecurity Framework 2.0 outcomes to pursue first by ranking them on implementation cost alone. Which consideration does the framework name as the basis f
- A single Cybersecurity Framework Subcategory is mapped to one control from the NIST control catalogue, and the outcome is then recorded as fully achieved on the strength of that one mapping. What does
- A water utility runs plant control systems, industrial sensors, and cloud-hosted corporate applications, and its engineers argue that the Cybersecurity Framework Core was written for corporate IT only
- A control catalog must be tailored to the system's requirements and risk
NIST SP 800-53 provides flexible security and privacy controls that address requirements from missions, laws, policies, standards, and guidelines. Selecting the entire catalog without scoping, tailoring, and allocating controls does not produce a risk-based architecture.
Trap Adopt the complete control catalog unchanged
9 questions test this
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- NIST's control baseline guidance states that controls implementing legislative, regulatory, or policy requirements are not tailored out of a baseline, yet it also recognises one situation in which rem
- A defence contractor's field system operates disconnected for long periods over intermittent low-bandwidth links, and its programme office asks whether the federal baseline it selected can be reduced
- A hospital's design team plans to implement every audit and accountability control in its selected baseline on all clinical workstations, arguing that a wider footprint is always the safer choice. Whi
- Implementing the entire NIST control catalogue without omission is sometimes presented as the most defensible route to a risk-based architecture, but the baseline guidance states a different objective
- Framework crosswalks indicate relationships rather than control equivalence
Mappings between standards provide a general indication of coverage, but relationships may be subjective and are not necessarily one-to-one. Compliance must therefore be validated against the source requirement and its scope instead of inferred from a crosswalk alone.
Trap Accept a mapped control as conclusive proof of compliance
4 questions test this
- Two documents are compared during a mapping: one clause of a sector standard and one control of an adopted framework, where each of the two contains an obligation that the other leaves out. Which set
- Two suppliers each publish a mapping from their own controls to the same NIST publication, and both label their relationships 'supports', yet an architect finds that the two mappings cannot be read th
- In a mapping between a national regulation and an organisation's control framework, two texts share almost no wording, yet carrying out either one of them produces the same protective result. Which ra
- The absence of a row in a published crosswalk is sometimes read as proof that a regulatory requirement has no counterpart in the framework an organisation has adopted. Which property of published mapp
- Requirement applicability follows organizational and operating context
The architect identifies relevant laws, regulations, contractual duties, and internal policies by examining mission, sector, jurisdictions, stakeholders, data processing, and services. A control cannot be justified as compliant until the requirement's subject, scope, and triggering conditions apply.
5 questions test this
- A retailer's baseline includes a control implementing a statutory breach-notification duty that binds only firms operating in a jurisdiction the retailer has now exited. The architect must adjust the
- An organization holds employee, customer, and health-related personal data across two jurisdictions, and its data dictionary uses one internal definition of personal information for all of them. Which
- A federal agency will place regulated mission data with a commercial cloud provider. The agency's architect must ensure the provider is bound to the same protection obligations the agency carries. Whi
- A defense supplier processes controlled unclassified information for one program only. Its architect wants the CUI protection requirements to bind as few components as possible while still protecting
- An architect must show which parts of a sector regulation the organization's Cybersecurity Framework outcomes address, using material NIST publishes online. Which resource supplies those mappings betw
- Legal counsel interprets legal obligations while architects translate them into controls
Security architects should obtain authoritative interpretations of laws and regulatory conflicts from qualified legal and privacy stakeholders. Their architectural role is to convert those interpretations into verifiable security and privacy requirements, not to make unsupported legal determinations.
Trap Let the architect independently resolve ambiguous law
3 questions test this
- Counsel has issued a written interpretation of how a data-residency law applies to a planned platform. The architect must now express that interpretation in a form that engineers can build to and asse
- A new state statute may or may not cover the categories of personal information a company holds, and the wording is contested. The architect needs an authoritative determination before selecting contr
- An architect cannot tell whether a sector privacy rule's encryption clause extends to archived backups held by a processor. Before any control is chosen, which product of the organization's legal and
- Organizational policy may impose controls beyond external minimums
Applicable requirements include internal policies and mission needs as well as external mandates. Meeting a regulatory minimum does not satisfy a stricter organizational baseline unless the authorized policy owner approves an exception or changes the policy.
Trap Stop control selection at the least demanding regulation
4 questions test this
- Some organizations mandate controls beyond the standard baseline they start from, such as phishing-resistant multi-factor authentication for all remote administrative access to production systems. Whi
- A Cybersecurity Framework 2.0 Organizational Profile can include a component that specifies the desired outcomes an organization has selected and prioritized, and that expresses its expectations to su
- A control that an applicable regulation mandates cannot be implemented on a legacy platform, and an alternative safeguard is proposed in its place. Which condition must the alternative satisfy before
- A bank's approved cryptographic standard requires stronger protection for stored customer records than the applicable regulation's minimum. A project team proposes building only to the regulation. Whi
- Each compliance requirement needs traceability to controls and evidence
A defensible architecture maps each source obligation to implemented or inherited controls, responsible owners, assessment methods, and retained evidence. This traceability exposes coverage gaps and lets an assessor follow a requirement from authority to operating proof.
6 questions test this
- An assessor asks the architect for the single document that gives an overview of a system's security requirements and describes the controls in place or planned to meet them, together with the system
- A traceability record states how each requirement's control will be verified, and each verification names an assessment method. One method obtains evidence by reviewing, inspecting, observing, or anal
- Two teams each assume the other maintains a control that satisfies a contractual obligation, and the control lapsed for a quarter without anyone noticing. Which element of the traceability record woul
- An architect must show which parts of a sector regulation the organization's Cybersecurity Framework outcomes address, using material NIST publishes online. Which resource supplies those mappings betw
- One assessment artifact states the objectives for a control assessment, the specific procedures to be executed against each control, and the roles and responsibilities for carrying them out, and it is
- An external auditor accepts that a contractual obligation is mapped to a named control with an owner, but asks the architect to demonstrate that the control actually operated last quarter. Which eleme
- Compliance scope boundaries must include dependencies that affect protected processing
The architecture defines systems, data flows, facilities, people, external services, and interconnections that can affect the regulated service or information. Arbitrarily excluding a connected dependency can invalidate both control design and compliance evidence.
Trap Limit scope to hosts that directly store regulated records
5 questions test this
- Federal risk management guidance warns that an authorization boundary drawn too narrowly, leaving out elements that support the same mission and carry comparable protection needs, imposes a specific p
- A payment gateway routes card data through an internal message broker that writes nothing to disk and holds each message in memory for a few seconds. The broker team argues that the component keeps no
- Scoping guidance for a regulated payment environment tells an assessed entity what starting position to take each year, before any component is excluded and the resulting scope is documented for the a
- A build pipeline rebuilds and redeploys a regulated trading platform automatically from a separate cloud account, and it holds no regulated data of its own. The compliance boundary currently lists onl
- A manufacturer's regulated payment environment is administered day to day by an outside support firm, and the compliance lead wants the assessment limited to the servers that store payment records. Wh
- GDPR reach can extend beyond an organization's location
An organization need not be established in the EU for GDPR obligations to apply when its processing relates to offering goods or services to people in the EU or monitoring their behavior in the EU. Physical establishment alone is therefore not a sufficient test of applicability.
3 questions test this
- An analytics vendor incorporated outside the Union places tags on European publishers' sites and profiles individual readers located there to predict their interests. It bills only the publishers. Whi
- A company with a sales and marketing branch in Dublin runs every customer system in a data centre outside the Union, and its counsel argues that the Regulation cannot reach processing performed abroad
- A foundation established outside the Union runs a free mobile application aimed at residents of several member states and receives no payment from any user. Which characteristic of that offering decid
- Outsourcing a service does not outsource the acquirer's accountability
An organization remains responsible for managing risks and obligations attached to its mission and information when a supplier performs the work. The architecture must allocate shared controls and evidence duties explicitly rather than assuming the provider's program satisfies the acquirer automatically.
Trap Treat supplier certification as a transfer of accountability
2 questions test this
- Explicit statements of a service provider's specific responsibilities, together with the expectations the customer may hold, belong in one named agreement document rather than being inferred from the
- Outsourcing systems and services reduces an enterprise's visibility into and control over the functions a provider performs, while the resulting risk to enterprise systems and data stays with the ente
- Supply chain requirements must flow down to relevant subcontractors
Controls implemented across the system life cycle often depend on prime contractors and their sub-tier suppliers. Contracts must identify which security, privacy, assurance, and reporting requirements flow down so that outsourcing depth does not break the control chain.
6 questions test this
- A system integrator's proposal includes several layers of suppliers and teaming arrangements the acquirer did not select. The acquirer has strong visibility into the integrator relationship and wants
- A telecommunications operator's shortlisted supplier will deliver a platform that depends on several fourth- and fifth-party providers. The operator must decide how far down the chain its security req
- A European retailer's payment processor engages an offshore analytics firm to handle part of the processing. The analytics firm then fails its data protection obligations. Under the processor provisio
- Delivery of a critical managed service depends on several of the supplier's own upstream providers, and an incident at any of them should reach the acquiring enterprise. Which requirement should the s
- The processor provisions of the General Data Protection Regulation restrict how far processing may be delegated when a controller has granted no standing approval for additional processors. What must
- A prime contractor will build an enterprise identity platform using three lower-tier development houses that the acquirer never contracts with directly. The acquirer needs its security requirements en
- Supplier assurance begins before selection and continues through the relationship
C-SCRM uses risk-based due diligence and assessment before selection or acceptance, followed by reviews and monitoring during performance. A one-time procurement questionnaire cannot address later ownership, development, vulnerability, or service changes.
Trap Perform supplier assessment only after contract award
6 questions test this
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- Assessing every supplier on an identical annual cycle starves the most important relationships of attention while burdening marginal ones with the same paperwork. Which basis does cyber supply chain g
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- Critical hardware components are examined for evidence of tampering when they arrive and are then placed into service for years. The assurance obtained at delivery decays while those components remain
- Cybersecurity supply chain evaluation of bidders and their proposed products has to produce a result usable as a weighted factor in a competitive enterprise platform buy, not a record filed afterwards
- Third-party agreements must define security notification duties
Notification agreements establish which incidents, vulnerabilities, component changes, or supply disruptions a supplier reports, to whom, and within what required timeframe. Without these terms, the customer cannot reliably meet its own response and reporting obligations.
5 questions test this
- A cloud payroll provider processes employee records solely on the documented instructions of a European client and discovers a personal data breach inside its own platform. Which notification duty doe
- A payment firm outsources card settlement to a managed provider, and the agreement leaves the timing of any incident report to the provider's judgement. The firm's regulator measures the firm's own fi
- A sole-source supplier manufactures a signalling controller that a rail operator cannot substitute at short notice. The operator's continuity plan depends on learning early when the supplier will be u
- Long-lived industrial control assets routinely outlive the support cycles of the firmware they run. Which supplier notification obligation gives the acquiring organisation time to plan a replacement b
- Supply chain guidance treats early warning of events that may have affected an acquirer's systems as essential, yet many supplier agreements oblige a report only once the supplier's own investigation
- Provenance and component transparency support supply chain trust decisions
Provenance records help track origin, ownership, custody, and changes so components can be validated as genuine and unaltered. An SBOM adds software-component visibility for vulnerability and dependency analysis, but does not by itself prove that those components are secure.
Trap Treat an SBOM as a product security certification
6 questions test this
- An architect must decide what evidence would justify trusting the internal composition of a mission-critical microelectronics part, including the origin of the materials and code within it. Which supp
- An enterprise standard requires a component record for every software item in a regulated platform. One widely used open source library that the platform depends on publishes no such record of its own
- A supplier offers its component record as proof that a delivered application contains no exploitable vulnerabilities, and asks the acquirer to waive further security assurance on the strength of it. W
- A component record delivered once at contract award describes a build that later supplier releases have changed, so the acquirer's dependency queries no longer describe the running software. Which agr
- Component records that arrive as free-text spreadsheets and portable documents with differing field names cannot be correlated across suppliers at the moment a widely used library flaw is announced. W
- A utility receives a component record with every software release from all of its suppliers and files each one in a document repository that nobody opens. Which addition converts that transparency int
- Privacy requirements apply across the complete data-processing lifecycle
Data processing includes collection, generation, use, transformation, logging, retention, disclosure, sharing, transmission, and disposal. Privacy architecture must therefore follow data and derived records through every lifecycle action rather than protect only stored databases.
4 questions test this
- A retailer's privacy assessment documents how customer records are collected, stored, and deleted. Its recommendation engine then creates new propensity scores about each customer that no customer eve
- An architect finds that customer records protected in the production database also appear in nightly backups, diagnostic files, and a reporting warehouse. Which activity gives the privacy program a co
- Which term names the collective set of life cycle operations that a system performs on data, spanning collection, generation, logging, transformation, use, disclosure, sharing, transmission, and dispo
- Which data action is being performed when an application writes complete transaction detail, including cardholder names and addresses, into diagnostic files, so that the resulting records fall inside
- Personal data collection and retention must be limited to a defined purpose
NIST guidance recommends minimizing the use, collection, and retention of PII to what is necessary for mission or business purpose and periodically reviewing holdings. Encryption reduces disclosure risk but does not justify collecting unnecessary personal data.
Trap Retain all encrypted PII for possible future use
6 questions test this
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- A marketing team asks to keep every archived customer record indefinitely, arguing that the archive is encrypted and that a future analytics project may eventually need the data. Which practice should
- An application must confirm that a user is at least eighteen years old. The product owner proposes collecting each user's full date of birth, while the architect proposes storing only an age-threshold
- A health insurer collected claims data to administer member benefits. A new analytics team wants to reuse those records to train a marketing propensity model unrelated to the benefits administration t
- PII confidentiality impact depends on context, not merely field names
Protection level considers identifiability, quantity, field sensitivity, context of use, obligations, access, and location. The same data element may create different harm when combined with other fields or used in a more sensitive context.
4 questions test this
- Which factor, under NIST's guidance on protecting PII, accounts for two directories that hold the same fields of name, address, and telephone number being assigned different confidentiality impact lev
- Which factor should raise the assessed confidentiality impact level of a research extract that carries no names and no account numbers, yet keeps a five-digit postal code, a date of birth, and a sex c
- Which factor justifies raising the confidentiality impact level of a customer record when a release adds place of birth and a parent's middle name, values many services accept for password recovery, t
- A state agency holds a small taxpayer dataset that only two analysts ever open, and it proposes a low confidentiality impact level on that basis. Which factor must be settled with legal counsel before
- Authorized data processing can still create privacy risk
Privacy risk includes problems individuals may experience from data processing even when confidentiality, integrity, and availability are not breached. A security risk assessment alone therefore cannot replace analysis of purpose, predictability, autonomy, and potential effects on individuals.
Trap Limit privacy analysis to unauthorized disclosure scenarios
3 questions test this
- Which activity evaluates the problems individuals could experience from a workforce analytics platform's authorized processing, and therefore remains necessary even after security testing of that plat
- A transit authority wants trip records processed for network planning without tying them to identifiable riders beyond what operations require. The processing is lawful and the records are retained fo
- Which privacy engineering objective is failing when the users of a fitness service repeatedly find their activity data used in ways they did not anticipate, although every one of those uses is authori
- De-identification requires analysis of residual re-identification risk
Removing direct identifiers does not necessarily prevent records from being linked back to individuals through remaining attributes or external data. The architect selects de-identification techniques and release controls according to the intended use and credible re-identification threat.
Trap Declare data anonymous after masking names alone
2 questions test this
- Which model bounds mathematically what an analyst can learn about any single individual from published statistical tables, without depending on assumptions about the outside data an adversary may hold
- Which category of attributes must be addressed before releasing a hospital research extract whose patient names and medical record numbers have been deleted, but whose every row still carries an admis
- Select and document a lawful basis before processing personal data
GDPR processing is lawful only when an applicable Article 6 basis supports the purpose, such as consent, contract necessity, legal obligation, vital interests, public task, or a qualifying legitimate interest. The controller should determine and document that basis before processing and provide the required transparency to the data subject; a technical ability or business desire to use the data is not a lawful basis.
- Embed privacy in processing design and default settings
Privacy by design integrates appropriate technical and organizational safeguards when processing means are chosen and while processing occurs. Privacy by default limits the amount collected, extent of processing, retention, and accessibility to what each specified purpose requires without relying on the individual to tighten permissive settings.
2 questions test this
- A hospital's new records system grants every clinician access to every patient record, and leadership plans to let departments request narrower profiles after go-live. Which default should the archite
- A retailer's loyalty programme switches every optional profiling model on for each member account at enrolment, and a member may turn those models off afterwards. Which element of the GDPR's data prot
- Consent must be specific, provable, and withdrawable
When consent is the selected GDPR basis, it must be freely given, specific, informed, and unambiguous, and the controller must retain evidence that it was obtained. Withdrawal must be as easy as giving consent and must stop future consent-based processing; consent is one possible lawful basis, not a universal prerequisite or permanent permission.
3 questions test this
- The GDPR requires a controller relying on consent to be able to show, for a named individual and a specific purpose, that valid consent was obtained before the processing began. Which platform capabil
- A fitness service captures marketing consent through a single in-app toggle, but a user who wants to stop that processing must post a signed form to a service address. Which consent condition does the
- A subscription platform presents one tick box that covers product analytics, partner marketing, and profile enrichment together. The wording is plain, the box starts empty, and users who decline all t
- Controller accountability continues when processors handle personal data
The controller determines the purposes and means of processing and must select processors that provide sufficient compliance guarantees. A written, binding processing agreement defines scope, duration, data, responsibilities, security, assistance, return or deletion, and documented instructions; delegating execution to the processor does not remove the controller's accountability to demonstrate compliant processing.
8 questions test this
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- A payroll platform provider processes employee records for its client and now proposes adding a model it designed itself, scoring attrition risk to shape its own product roadmap. The client remains th
- A controller receives an access request covering records that live only inside its processor's platform, and the processor answers that its contract does not oblige it to help. Which contractual term
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Systems must make applicable data-subject rights executable
GDPR rights include information and access, rectification, erasure, restriction, portability, objection, and safeguards concerning automated decisions and profiling. The architecture must therefore support finding data by subject, supplying intelligible copies, correcting or deleting records, restricting downstream use, exporting portable data, propagating objections, and governing automated-decision workflows.
4 questions test this
- A retailer keeps customer personal data in an order platform, a support tool, and a reporting warehouse, and no shared subject identifier links them. The privacy team must answer access and erasure re
- The right to data portability lets a data subject receive the personal data she provided in a form another controller can ingest without manual re-entry, and have it transmitted directly where that is
- A controller receives an access request covering records that live only inside its processor's platform, and the processor answers that its contract does not oblige it to help. Which contractual term
- A retailer keeps customer personal data in an order platform, a support tool, and a reporting warehouse, and no shared subject identifier links them. The privacy team must answer access and erasure re
- Privacy breach notification follows risk, recipient, and role
Under GDPR, a processor notifies its controller without undue delay, and the controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms. When high risk is likely, the controller also communicates with affected data subjects without undue delay unless a specified exception, such as effective protection that renders the data unintelligible, applies.
3 questions test this
- A hosting provider that processes personal data on behalf of a client discovers that a customer database was copied without authorisation. The provider is not the controller for that data. Which actio
- An attacker exfiltrated an archive of customer records that was encrypted with keys held only in a separate hardware module the attacker never reached. The controller has already notified the supervis
- Hours after confirming a breach of a customer database, a controller's forensic team still cannot say how many records were taken, and the legal lead wants to hold everything back until the final repo
- A business impact analysis drives recovery requirements and priorities
The BIA determines process criticality and outage impacts, identifies supporting resource requirements, and establishes recovery priorities. A general risk assessment informs the BIA but does not replace its continuity-focused deliverables.
Trap Use vulnerability scan severity to set recovery order
7 questions test this
- The total amount of time a system owner will accept for a mission or business process outage is recorded during contingency planning as one figure. It includes all impact considerations and bounds the
- Continuity planning requires one determination before any decision about which services must keep running through a disruption and which may be suspended. Cyber resiliency guidance calls identifying t
- An investment case for a second processing facility must show what an extended interruption would cost before funds are committed. One output of the business impact analysis expresses that cost in ope
- A print server holds almost no data and is inexpensive to replace, yet the contingency plan restores it ahead of several costly database platforms. An auditor challenges that ordering as inconsistent
- A financial services firm must decide the order in which forty systems are restored after a regional outage. The architect will accept only a documented statement of how badly each supported business
- Criticality rankings and a restoration sequence for a payroll process are available from a completed impact study. The study as delivered still does not state what must be present at the alternate cap
- A hospital's enterprise risk register is complete and current, and leadership asks whether anything further is required before contingency strategies for its clinical systems are selected. The archite
- RTO limits service interruption while RPO limits tolerable data loss
The recovery time objective expresses how quickly a system or process must be restored after disruption. The recovery point objective expresses the acceptable age of restored data and therefore drives backup or replication frequency.
Trap Use RTO to specify the acceptable backup age
7 questions test this
- A distributor can tolerate a one-day interruption of its warehouse system. Its budget rules out maintaining a duplicate facility that is fully configured and staffed, but the recovery window is far to
- The total amount of time a system owner will accept for a mission or business process outage is recorded during contingency planning as one figure. It includes all impact considerations and bounds the
- A requirement states that after any failover, no more than the last fifteen minutes of committed transactions may be missing from the restored database. The figure will drive how often transaction dat
- A rule requires an insurer to keep closed claim records retrievable for seven years, long after the systems that created them are replaced. Contingency documentation must record that seven-year obliga
- A records system may lose at most one day of data after a disruption, and it must be back in service within two hours of one. Each of the two figures governs a different parameter of the recovery desi
- Backup media for a hospital's clinical system are held in a commercial vault three hundred kilometres away, staffed only during weekday business hours. The system's recovery objective assumes the medi
- A claims platform may be unavailable for at most four hours before the insurer suffers unacceptable harm to its operations. Within that ceiling the architect sets a two-hour target for returning the p
- Alternate capabilities must avoid the primary environment's credible common failures
Relocating processing or storage adds resilience only when the alternate capability has suitable capacity, dependencies, accessibility, and separation from threats affecting the primary site. Nominal redundancy inside one shared failure domain can still leave a single point of failure.
6 questions test this
- A distributor can tolerate a one-day interruption of its warehouse system. Its budget rules out maintaining a duplicate facility that is fully configured and staffed, but the recovery window is far to
- A regional bank's continuity team proposes an alternate processing site four kilometres from the primary data centre. The proposed site sits inside the same river flood plain and draws its power from
- Backup media for a hospital's clinical system are held in a commercial vault three hundred kilometres away, staffed only during weekday business hours. The system's recovery objective assumes the medi
- A data centre buys two circuits from different carriers to reach its alternate site. Both carriers hand their circuits to the building through one street conduit, and both lease capacity on the same r
- Criticality rankings and a restoration sequence for a payroll process are available from a completed impact study. The study as delivered still does not state what must be present at the alternate cap
- A logistics firm keeps its only backup copies on a storage array standing in the same computer room as the production servers those copies protect. The architect must correct the arrangement before th
- Resilience includes operating under adversity and recovering essential functions
A resilient architecture anticipates that some preventive controls will fail and preserves essential operations, possibly in a degraded state, while enabling rapid recovery. Boundary protection alone is insufficient for attacks, environmental disruptions, and human errors that penetrate or bypass it.
5 questions test this
- Continuity planning requires one determination before any decision about which services must keep running through a disruption and which may be suspended. Cyber resiliency guidance calls identifying t
- A design assumes preventive controls will sometimes be defeated. It must let defenders change course while an intrusion unfolds, rerouting traffic, suspending non-essential services or isolating a zon
- A water utility's treatment control system must not stop when it encounters conditions it cannot process correctly. The architect specifies that on those conditions the system continues only a restric
- A design keeps a system's essential business functions running while an intrusion is under way. It accepts that the intrusion may go undetected, or be misread as user error, and that compromised compo
- A cyber resiliency technique defines and separates system elements by criticality and trust, so that a compromise originating in a low-trust environment such as corporate email cannot propagate into t
- Testing, training, and exercises validate different aspects of contingency readiness
Testing validates recovery capabilities, training prepares personnel for their assigned duties, and exercises reveal coordination and planning gaps under scenarios. A tabletop discussion cannot provide the same assurance as executing technical recovery in an operationally representative environment.
Trap Treat a plan walkthrough as proof of technical failover
3 questions test this
- A hospital revised its information system contingency plan after consolidating two data centres, and the recovery procedures now name different facilities and teams. Test, training and exercise (TT&E)
- Recovery team members at a water utility have never been told which duties the information system contingency plan assigns to them. The programme coordinator is sequencing the coming year's test, trai
- A test, training and exercise programme separates tests from exercises. A test evaluates whether a system or one of its components actually operates the way the plan requires. Which characteristic of
- Maximum tolerable downtime bounds recovery objectives
Maximum tolerable downtime is the total duration a mission or business process can be disrupted without significant harm. The system RTO plus the time needed to recover lost work must not exceed that limit.
5 questions test this
- A settlement system's recovery target is set at the maximum tolerable downtime of the process it supports. Contingency planning guidance states that the target must normally be shorter than that limit
- A reporting system supports a mission essential function whose maximum tolerable downtime is fixed by a federal continuity directive. The system's own owner proposes a longer downtime limit, arguing t
- Recovery procedures for a wide area network with many interdependent components are written as a stepwise sequence in which the order of restoration steps must reflect the system's maximum tolerable d
- A contingency planning team has completed its impact estimates, but the system owner has never stated how long the supported mission or business process may be disrupted before significant harm occurs
- A trading process may be interrupted for at most six hours. The proposed design returns the platform to service five hours after a disruption, and re-entering the queued trades then takes a further ni
- Resilience plans must be selected and coordinated by scope
A BCP sustains mission or business processes during and after disruption, while a COOP plan sustains an organization's mission-essential functions, typically at an alternate site. A cyber incident response plan addresses malicious cyber events, whereas a disaster recovery plan relocates information-system operations after a major facility disruption. An ISCP restores an individual system at its current or an alternate location and may operate alone or under the broader plans.
4 questions test this
- A federal agency must be able to perform its mission essential functions from an alternate site for up to thirty days after a disruption makes its headquarters unusable, and then return to normal oper
- During a regional outage, an insurer must ensure that only designated officials answer questions from the public and the press, and that consistent status reports reach its own staff. Which plan in th
- Two planning disciplines are commonly confused. One concerns the ability to continue critical functions and processes during and after an emergency event. The other provides the steps needed to recove
- Contingency planning guidance requires an organisation's business continuity plan, disaster recovery plan and individual system contingency plans to be coordinated during development and whenever they
- Contingency plans must track material change
Contingency plans should be reviewed on an organization-defined schedule and whenever significant changes affect systems, interconnections, suppliers, facilities, personnel, responsibilities, or organizational requirements. Material changes may require updating the BIA, recovery priorities, procedures, contacts, agreements, and controlled plan copies so the documented strategy remains viable.
- Contingency execution separates activation, recovery, and reconstitution
Activation and notification applies outage criteria, declares the plan, assesses the disruption, and mobilizes affected parties; recovery restores prioritized capabilities using the selected strategy. Reconstitution validates recovered data, functionality, and controls before resuming normal operations and formally deactivating the plan.
- Industry-standard scope follows the protected data and systems that can affect it
For standards such as PCI DSS, scope includes the protected data environment and system components that store, process, transmit, or can affect the security of that data. Segmentation can reduce scope only when its effectiveness is established and maintained.
6 questions test this
- Under PCI DSS scoping guidance, which condition must be satisfied before an existing subnet boundary between the payment systems and the rest of an internal network counts as segmentation that reduces
- A retailer's directory, patching and log servers sit outside the cardholder data environment, yet they authenticate to and push updates into the payment servers that store account data. The architect
- Under the PCI Data Security Standard, which of the following sets of components falls inside the assessment boundary of an organisation whose payment systems share one flat internal network with no co
- A retailer is rebuilding its payment platform on cloud microservices that are created and destroyed continuously. The architect must keep the PCI DSS boundary accurate across those ephemeral workloads
- Before each annual assessment a merchant must identify every location and flow of cardholder data, together with every system that could impact the cardholder data environment if it were compromised.
- Which property determines whether employee laptops on a corporate network, which can reach the shared-services jump server that administrators use to sign in to the cardholder data environment, must t
- Service-provider assurance evidence covers only its stated services and responsibilities
An attestation or assessment report must be checked for entity, service, location, period, exclusions, and customer responsibilities. The existence of current provider evidence does not establish that the customer's configuration and retained controls are compliant.
Trap Accept a provider attestation without reviewing its scope
6 questions test this
- A shortlisted cloud service appears in a public assurance registry solely on the strength of a questionnaire the provider completed about its own controls. The architect requires assurance validated b
- When a retailer outsources hosting of its payment application to a service provider that holds current independent compliance evidence for that hosting service, what is the effect on the retailer's ow
- A managed hosting provider's assurance report excludes the data-centre operator it depends on, presenting those controls as another organisation's responsibility. The architect must still cover the de
- A merchant and its hosting provider disagree over which of them patches the payment servers. The architect wants one artefact that records, requirement by requirement, which party performs each contro
- In a service provider's assurance report, what is the name for the controls that the report assumes each customer will implement in its own environment, and on which the auditor's conclusions about th
- A payment gateway offers its current Attestation of Compliance as evidence for a merchant's own assessment. The gateway sells several distinct services, of which the merchant uses two. What must the m
- ISO/IEC 27001 certification is bounded by the certified ISMS scope
Certification provides independent confidence that the organization operates an ISMS conforming to the standard within the certificate's defined scope. It is not a blanket guarantee that every product, location, or information system is secure.
6 questions test this
- A cloud service the architect intends to use is delivered from a region and a business unit that the supplier's ISO/IEC 27001 certificate may not cover. The supplier repeats that the company is certif
- What does a valid ISO/IEC 27001 certificate, issued to a supplier by a certification body that is itself nationally accredited, establish on its own about that supplier at the level of assurance the s
- A group holding company is certified to ISO/IEC 27001, and the architect's data will be handled at a subsidiary site acquired after the last certification audit. The board treats the group certificate
- Which evidence should an enterprise architect request in order to confirm that two shortlisted suppliers, each certified to ISO/IEC 27001, encrypt the backups holding the organisation's data, a specif
- A vendor answers a request to evidence a security appliance's own protection functions by supplying its corporate ISO/IEC 27001 certificate. The architect needs independent evaluation of the appliance
- Which body issues an organisation's ISO/IEC 27001 certificate after auditing its information security management system, given that the standard itself is published jointly by two international standa
- A Protection Profile states reusable needs while a Security Target describes a specific evaluation target
Under Common Criteria, a Protection Profile expresses implementation-independent security requirements for a class of products. A Security Target identifies the particular target of evaluation and the functional and assurance requirements against which that target is evaluated.
Trap Use a Protection Profile as the evaluated product's specific claim
5 questions test this
- Common Criteria defines one document that states implementation-independent security needs for a type of product, and another that states the security requirements one identified product is evaluated
- A utility has commissioned an independent Common Criteria evaluation of a substation gateway from an accredited laboratory. The project board asks the architect what the laboratory will measure the ga
- A supplier is asked to evidence what its firewall appliance was evaluated to do under Common Criteria. It replies with the Protection Profile that its entire product family claims conformance to. The
- An architect is drafting the security section of a competitive tender for hardware security modules. The organisation wants suppliers with quite different internal designs to be able to bid, and wants
- An internal auditor treats the Common Criteria Protection Profile published for a technology class as the record of what the organisation's installed product actually does. The architect must explain
- Evaluation assurance measures confidence in evaluated claims rather than absolute security
A Common Criteria evaluation determines whether a defined target satisfies specified security properties at a stated assurance depth. A higher assurance package increases evaluation rigor but does not prove freedom from all vulnerabilities or suitability for every operating environment.
Trap Select the highest EAL as proof of universal product security
4 questions test this
- A vulnerability is publicly disclosed in a product holding a current Common Criteria certificate, and it concerns functionality that sat inside the evaluated boundary. A risk committee asks whether th
- An architect compares two evaluated storage encryptors, one of which carries a higher Common Criteria assurance package than the other. The board asks what that higher package, taken on its own, tells
- A programme team proposes requiring the highest available Common Criteria assurance package for every component of a new payments platform, including low-risk ancillary components. The architect must
- An architect requires independent confirmation that the mathematical properties of a product's cryptographic algorithms are sound. The product already holds a current Common Criteria certificate issue
- PCI DSS establishes a payment-account protection baseline
PCI DSS defines baseline technical and operational requirements designed to protect payment account data, including cardholder data and sensitive authentication data. Its intended audience spans entities involved in payment-card processing, including merchants, processors, acquirers, issuers, and service providers, rather than only the organization that accepts the card at checkout.
Architect for Governance, Risk, and Compliance
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Security Architecture Modeling
Select a security architecture approach
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Verify and validate the security design
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Verification asks whether the design meets its specified requirements
Verification compares architecture or implementation evidence with defined requirements, constraints, and design criteria. It answers whether the system was built according to specification, not whether the selected specification satisfies the user's operational need.
Trap Acceptance testing focused on fitness for operational use
6 questions test this
- A verification report for a completed identity broker design lists items the security specification never addressed, which surfaced only while the build was exercised. Which class of finding must veri
- NIST control guidance requires a developer to perform security testing and evaluation at a stated frequency, within stated bounds on how rigorous that work must be and how many artifacts it must span.
- An acquirer wants the advertised security mechanisms of a delivered information system exercised against the system's specification, rather than an open-ended hunt for unknown weaknesses in the runnin
- Systems security engineering guidance requires each planned verification action for a security design to state what will be verified and which verification method applies. One further element must be
- Which of the three assessment methods defined in NIST's technical guide to information security testing and assessment applies when a completed security design description must be judged against its s
- Systems security engineering guidance requires the facilities, equipment and emulation services that a verification procedure depends on to be identified, planned for, and obtained before the procedur
- Validation asks whether the resulting system is fit for intended use
Validation evaluates whether the system, in its operational context, satisfies stakeholder needs and intended use. A design can verify against an incomplete requirement set yet fail validation because it solves the wrong operational problem.
Trap A requirements trace showing every written requirement was implemented
5 questions test this
- Among the security outcomes that systems security engineering guidance expects the Validation process to produce, one is stated from the stakeholders' side and concerns what they will actually be able
- Validation of a trading platform's security design must show that it holds up as an adversary or a misusing insider would exercise it in service, not merely that documented functions operate. Which va
- Systems security engineering guidance closes an improvement feedback loop by recording one class of post-deployment information and correlating it back to the validation activities and results that pr
- A programme intends to decide after its pilot whether a new zero-trust design performed well enough for the business. The architect objects that the Validation process requires something to be establi
- A records gateway passes every verification action against its documented system requirements, yet the archivists who must use it report that it blocks the retention workflow the programme exists to s
- Acceptance testing decides readiness against agreed acceptance criteria
Functional acceptance testing demonstrates that required functions and security behavior satisfy agreed acceptance criteria in the intended context. Passing developer unit tests is supporting evidence, but it does not by itself demonstrate satisfaction of the complete acceptance criteria.
6 questions test this
- Every module of a new key-management service has been exercised in isolation and each one passes. The acceptance criteria call for evidence about the assembled service as a whole. Which of the develop
- NIST defines a test plan as a document outlining the specific steps performed for a test, including the required logistical items and one further element per step. An acceptance test procedure current
- A supplier's delivery package for an authorization service contains passing developer module tests and a clean code analysis report. The agreement requires a demonstration that the required security f
- A supplier submits passing developer unit-test reports as proof that its delivered authentication service satisfies the security acceptance criteria written into the contract. Those criteria call for
- During transition, once security activation and checkout are complete, the results of the installation, operational and enabling-system checkouts are reviewed together to decide whether security perfo
- Systems security engineering guidance directs an acquirer to place a set of security provisions in the supplier agreement, among them the terms stating what the supplier must demonstrate before the de
- Regression testing detects whether change broke previously satisfied behavior
After a modification, regression testing reruns relevant prior tests to find unintended effects in unchanged functions and controls. Testing only the newly changed feature can miss a security property that the change indirectly invalidated.
Trap Retesting only the new functionality introduced by the change
5 questions test this
- Secure software development guidance directs a project to add dedicated cases to its automated test suite so that later changes cannot quietly bring back defects the team has already dealt with. Which
- A team proposes to retest only the session-handling feature it modified. The architect warns that a modification can invalidate a protection the change never touched, leaving such an effect undetected
- Security-focused configuration management guidance calls for a further security impact analysis once a change has already been implemented and tested. That later analysis confirms the change was imple
- A change to a customer portal has been installed in production under an approved change record. NIST control guidance requires a follow-on activity confirming that the controls the change touched stil
- A change to a cryptographic library is delivered with a brand-new test suite written only for the replacement library's behaviour. The architect objects that unintended effects in functions the change
- Security functional tests must cover permitted and prohibited behavior
A useful functional test demonstrates both that authorized operations succeed and that disallowed operations are prevented. Positive-only testing can verify availability of a feature while leaving authorization failure paths untested.
3 questions test this
- An identity design's acceptance suite confirms that provisioning grants each role the entitlements its definition promises, and every executed case passes. The design also requires that access be with
- A treasury platform's security requirements state that no individual may both submit and approve the same payment. The acceptance suite already confirms that submitters can submit and that approvers c
- A supplier's security acceptance run for a claims service was executed end to end under one fully entitled test account, and every case passed. The requirements restrict several operations to named ro
- Verification depth should be proportional to risk and criticality
Test scope, depth, detail, and rigor should provide the confidence required for the most significant adverse effect that can occur and the applicable assurance needs. Applying the same shallow test set to every component can waste effort on low-consequence elements and under-test elements whose failure has severe consequences.
3 questions test this
- Systems security engineering guidance publishes design principles for trustworthy secure systems. One principle states that the rigor with which an engineering activity is conducted provides the confi
- An architect must maximize confidence that a reference monitor's security policy model is complete for its scope of control and self-consistent, and the program accepts the cost and specialist effort
- A verification plan for a payments platform allocates an identical two-day test window to every component, from the marketing content service to the hardware security module integration. The architect
- Fuzz testing targets failures caused by unexpected input
Fuzzing repeatedly supplies malformed, unexpected, or generated inputs and monitors for crashes, hangs, memory faults, and other anomalous behavior. It complements specification-based tests by exploring cases developers did not enumerate, but it does not establish complete correctness.
3 questions test this
- A robustness campaign drives automatically generated, malformed inputs into an embedded telemetry parser and monitors the target after each one. The campaign's primary findings are the anomalies its i
- A specification-derived security test suite for a message broker passes every case it contains. Automated generation and injection of unexpected input is then added to the assurance plan. Which gap in
- A two-week automated malformed-input campaign against a certificate parser completes with no crash, hang or memory fault recorded. The supplier proposes to record the parser as correct in the assuranc
- Penetration testing demonstrates selected exploitable attack paths
Penetration testing attempts to exploit vulnerabilities in a defined scope to show how controls fail together and what access or impact is achievable. A successful test provides strong evidence for the demonstrated path, while an unsuccessful test does not prove that no other path exists.
Trap Treating failure to exploit during a time-boxed test as proof of absence
5 questions test this
- A penetration test report documents one chain: a misconfigured directory permission yielded a service credential, which the testers then reused to reach the payment service. The board asks what the re
- A hospital's architect is asked to approve an authorized attack engagement run against live clinical systems using real exploits. Experienced testers will conduct it, and careful planning and notifica
- An automated vulnerability scanner reports only the possible existence of a weakness in a customer-facing service, and the organization must justify remediation funding. What does the attack phase of
- An architect needs evidence of how far an attacker could reach after compromising one ordinary employee workstation. The engagement must begin from the access a standard employee already holds and mus
- A two-week authorized attack simulation against a trading platform ends without the testers reaching the order database, and the agreed scope excluded the settlement network. Management proposes recor
- An attack vector combines a source, a vulnerable processor, and malicious content
NIST defines an attack vector as a segment of the pathway an attack uses to access a vulnerability. Characterize each vector by the source of malicious content, the potentially vulnerable processor, and the nature of the malicious content so reviewers can identify where that segment can be detected or stopped.
Trap An attacker profile and motive
7 questions test this
- A design verification review records one segment of an attack pathway as a malicious attachment that the organization's perimeter mail server receives and processes. The reviewer states that the segme
- A single phishing attack decomposes into five sequential attack vectors, and the actual exploitation occurs only in the last of them, when a vulnerable email client renders the attachment. Which benef
- Design verification checklists require each recorded segment of an attack pathway to be described so that reviewers can judge where that segment could be detected or blocked. Which triple of attribute
- NIST's data-centric threat modeling guidance treats a scenario paired with the ordered sequence of attack vectors that could realize it as an attack model rather than a complete threat model. Which fu
- An acceptance test confirms that a hardened helper application on user workstations no longer renders untrusted attachment types. The threat model records the matching segment as attachment content de
- A verification record describes one segment of an attack pathway by naming where the malicious content originates, which component would process that content, and what the content itself is. Which art
- A design team argues that its threat model is complete because every network path into the payment service has been enumerated. A reviewer notes that a help desk agent resetting a password for an impe
- Threat likelihood and impact must be estimated separately
Likelihood addresses the possibility that a threat event will occur and result in adverse impact, while impact addresses the magnitude of harm to operations, assets, people, or objectives. A rare catastrophic scenario and a frequent minor scenario therefore require distinct treatment even if a simple score ranks them similarly.
7 questions test this
- A threat event whose consequences would be catastrophic is nevertheless assigned a low overall risk level because the event is almost never initiated. NIST's risk determination guidance names the fact
- A risk register for a logistics platform gives each modeled scenario a likelihood of occurrence and an impact severity, and the two ratings were prepared by different analyst teams. NIST's risk-assess
- An architect adds out-of-band backups that shorten the outage following a ransomware event but do nothing to prevent the intrusion itself. The verification review must update one estimate for that sce
- An architect must separate two design risks that received the same composite score: a rare regional flood that would halt trading for days, and a weekly credential-stuffing burst that briefly slows lo
- An overall likelihood value for a threat event is reported using only the estimate of the likelihood that adversaries will initiate that event. NIST's guidance requires two values to be combined for t
- An insurer's assessment carries one moderate harm figure for a fraud scenario against its claims portal, taken from a single successful attempt. Nothing in the scenario description prevents the attemp
- Twelve moderate risks recorded separately in one assessment all depend on the same authentication service and would therefore materialize together. NIST's guidance on refining assessment results addre
- Predisposing conditions and vulnerabilities shape scenario likelihood
A threat source does not create the same risk in every architecture; exposure, susceptibility, existing controls, and exploitable weaknesses affect whether its event can succeed. Verification should test the assumptions used to estimate those conditions rather than treating likelihood as an adversary attribute alone.
5 questions test this
- A platform passed its security acceptance tests two years ago and its architecture has not changed since then. The reviewer argues that the original likelihood ratings can no longer be relied upon. Wh
- The same network-borne threat source is rated far less likely to cause harm in a stand-alone control system than in an internet-facing one, even though the source itself is described identically in bo
- A verification review confirms that every scanner-reported software flaw in a new platform has been closed. It also finds that all enclaves authenticate through a single identity provider with no alte
- An architect's data tier uses no database management system of any kind, so the review removes SQL injection threat events from the assessed set. A reviewer asks which documented concept justifies rem
- Several threat events in a completed assessment have no vulnerability and no predisposing condition mapped to them, which NIST's guidance says gives them a very low likelihood of resulting in adverse
- Gap analysis compares corresponding baseline and target elements
A design gap is established by comparing required target capability with the existing or proposed implementation and evidence. The analysis distinguishes elements to carry forward from those to add, remove, or replace, avoiding a generic findings list with no target-state trace.
Trap Counting scanner findings without mapping them to target requirements
4 questions test this
- A supplier delivers what it calls a gap analysis for a payment platform. The document is a ranked list of scanner findings with severity counts, and no entry refers to any capability the approved targ
- A security architect must assess a control that exists only as an approved design specification, because construction starts next quarter. The verification lead argues that no gap can be recorded unti
- A gap analysis for a lending platform lists every target control the estate does not yet provide. Each current-state entry was copied from the system security plan's implementation statements, and non
- A gap register for a stand-alone laboratory system reports one hundred and forty unmet target requirements, among them cloud-service and remote-maintenance controls for capabilities the system does no
- Threat-model results should focus verification on credible failure paths
Threat scenarios, affected assets, vectors, preconditions, and expected consequences provide inputs for selecting abuse cases and assurance activities. This trace lets reviewers test whether proposed controls interrupt the modeled path instead of testing controls in isolation.
3 questions test this
- A rail operator's threat model records, for every scenario, the harm the business would suffer if the modeled path completed. The release acceptance plan checks only that each named control behaves as
- A design review is required to confirm more than that a design answers the risks its threat model lists. Secure-development guidance adds a second check, applied to the model itself. What does that se
- A payment team's threat model records a scenario in which a stolen session token is replayed against the refund API. The acceptance test plan for the release currently contains only functional tests o
- Material design or threat changes require threat-model revalidation
A threat model is valid only for its documented system boundary, assumptions, technology, and threat context. New trust relationships, data flows, deployment environments, adversary behavior, or mitigations can invalidate prior conclusions and call for reassessing the affected conclusions.
Trap Reusing the approved threat model unchanged for every later release
6 questions test this
- An approved threat model covers a payroll application hosted in the organization's own data center. The same binaries will now run on a public cloud provider's managed platform, with no change to the
- Six months after a threat model was approved, a public adversary-behavior knowledge base adds a technique that bypasses one of the modeled mitigations for the same platform. Which element of the model
- An organization's change process must state when the security impact of a proposed system change, including its effect on the approved threat model, is analyzed. At which point does control guidance p
- A supplier delivers a subsystem whose implementation deviates from the design specification the security architecture approved. Acquisition guidance requires updated threat modeling and vulnerability
- To recover throughput, operations remove a message-inspection gateway that the approved threat model credits with interrupting two attack scenarios. Interfaces and data flows are otherwise unchanged,
- A release process reuses the same approved threat model for every release, recording that no re-review is needed while the feature set stays stable, regardless of infrastructure or dependency changes.
- A mitigation should measurably alter a modeled risk scenario
A proposed safeguard is relevant when it reduces the probability of successful exploitation, limits the resulting harm, improves detection and response, or removes a required precondition. Merely associating a control family with the affected asset does not demonstrate treatment effectiveness.
8 questions test this
- A rail operator's design review examines a containment safeguard whose introduction leaves the modeled compromise likelihood unchanged, while an infected maintenance workstation can no longer reach si
- A hospital's design review package supports a new data-loss control with one figure: the percentage of servers on which the agent is installed. The board wants evidence that the control is producing i
- A modeled scenario has a clinician exporting a full patient record set during a night shift, and blocking that export would stall genuine emergency care. The design must instead ensure the security op
- Which element must a design package add when its only justification for a proposed safeguard is that the affected asset is mapped to the relevant control family, and the verification team declines to
- A published vulnerability in a plant historian scores high on its vendor-supplied severity, but the architect's design places the host on an isolated segment reachable only from a hardened jump host.
- A rail operator's design review examines a containment safeguard whose introduction leaves the modeled compromise likelihood unchanged, while an infected maintenance workstation can no longer reach si
- A modeled intrusion requires the adversary to reach a substation management interface from a corporate user subnet, and the architect wants the design to remove that requirement rather than make it le
- Which systems security engineering process provides objective evidence that a segmentation design, once in use, fulfills its business or mission objectives and stakeholder protection needs in its inte
- A compensating control must satisfy the original security intent
When the preferred control is infeasible, a compensating control should provide comparable protection for the same requirement and threat, within the actual environment. Cost or convenience alone does not establish equivalence; the rationale and remaining exposure require evidence and approval.
Trap Any cheaper control from the same control family
5 questions test this
- A payment organization is able to meet a defined requirement as written, but its security team designs its own method of meeting the same requirement objective and documents how that method achieves i
- A baseline control cannot be implemented on a real-time process controller, so the architect substitutes a different control from the catalogue and the tailoring record notes only which control was sw
- Which tailoring action accounts for the removal of a mobile-device control from a system's baseline when the system contains no mobile components at all and no substitute control was recorded for the
- No single available control matches the protection of the baseline control that had to be tailored out, so the architect argues that three existing layers around the asset jointly close the gap. Which
- A trading floor's shared consoles cannot run the baseline session-lock control, so the architect substitutes an alternative catalog control. The design package demonstrates that the substitute gives c
- Alternative solutions should be compared across effectiveness and constraints
A trade study compares how candidate designs satisfy security requirements while accounting for cost, performance, interoperability, usability, lifecycle, and operational constraints. Selecting the technically strongest control without considering mission consequences can produce a design that fails validation.
9 questions test this
- Which trade-space factor rules out a candidate design that protects partner traffic with a proprietary tunneling protocol the partner agencies' own security gateways cannot terminate, when exchanging
- Which trade-space factor rules out a candidate design that protects partner traffic with a proprietary tunneling protocol the partner agencies' own security gateways cannot terminate, when exchanging
- Two candidate designs for a national tax platform both satisfy its confidentiality requirement, and the stronger design would consume the funding already reserved for the fraud-detection programme. On
- Two candidate designs for a national tax platform both satisfy its confidentiality requirement, and the stronger design would consume the funding already reserved for the fraud-detection programme. On
- Which basis of comparison captures the difference between two candidate controls that satisfy the same security requirement when one of them needs two specialist operators for the ten years the platfo
- Which analysis establishes whether each candidate solution class for a national identity service can actually be built and operated with the technology and staff available, before those classes are sc
- Three candidate designs each satisfy the confidentiality requirement for a national payments platform, and the architect must choose one on the basis of cost, schedule, interoperability and operationa
- Three candidate designs for a new settlement platform will be compared at design review, and the architect must fix in advance how protection strength and operational limits will be scored so the even
- Which factor did a selection fail to weigh when the candidate control offering the strongest protection was chosen and the resulting design then failed acceptance because it breached a documented timi
- Defense in depth uses complementary barriers against common failure paths
Layered controls are useful when they act at different points or with different failure modes in the threat scenario. Duplicating the same mechanism at several locations can preserve a common-mode weakness and should not be assumed to provide independent assurance.
Trap Multiple copies of one control with the same dependency and failure mode
7 questions test this
- An insurer's acceptance test drives one malformed session into a newly layered design. The gateway, the application and the database each raise the same block and the operations team cannot tell which
- An insurer's acceptance test drives one malformed session into a newly layered design. The gateway, the application and the database each raise the same block and the operations team cannot tell which
- A validation team is told that an estate already resists common failures because separate programmes bought different products over ten years. Component analysis shows those products embed the same cr
- An energy utility's design review board is shown a layered filtering claim. The same vendor's engine runs at the perimeter, on the hypervisor and on every host. All three instances draw their rules fr
- A national postal operator's architect allocates malicious-code protection to the mail gateway, the web proxy and the endpoint. The design reviewer will not accept the three allocations while a single
- A research agency must keep audit records readable after one platform is compromised, so its validated design places the logging service on a different operating system and a different technical stand
- Two authentication barriers guard a settlement interface, and each was accepted as an independent layer. Verification shows that both resolve account state through a single shared directory service, s
- Residual risk remains after controls and requires explicit disposition
Verification of a mitigation does not prove that the risk has been eliminated. The post-treatment likelihood, impact, assumptions, and uncertainty must be recorded so the authorized decision maker can accept the residual exposure or require further treatment.
Trap Closing the risk automatically when its planned control passes a test
5 questions test this
- A verified encryption control moves a modelled breach scenario from severe to moderate, and the design package presents that new rating on its own. The authorizing official must now dispose of what re
- Regression testing confirms that a re-engineered authorization control still blocks the modelled abuse case in the laboratory build. Production carries two partner integrations that the laboratory bui
- A broadcaster's residual-risk entry for a newly verified control gives one post-treatment loss figure, and the reviewing official cannot tell whether the analysts had firm evidence or a rough judgemen
- A water utility's firewall redesign passes validation, and the modelled exposure falls only while the plant network stays physically separate from the corporate estate. The design package records the
- A new segmentation control passes every acceptance case, and the recalculated exposure still sits above the tolerance the risk committee published. The programme now seeks an acceptance signature from
- A tabletop exercise validates plans and decisions through facilitated discussion
A tabletop presents a scenario to participants who discuss responsibilities, coordination, decisions, and expected actions. It is well suited to exposing unclear authorities and procedural gaps but does not demonstrate that production technology can execute the response under load.
Trap Treating successful discussion as proof of technical failover capacity
8 questions test this
- Which tabletop exercise document carries the observations recorded during the event and the recommendations for enhancing the exercised IT plan, developed after the facilitated debrief against evaluat
- A high-impact system's contingency plan requires processing to move to the alternate location. The organization currently exercises the plan every year with a tabletop only. Which additional event doe
- A bank's leadership will not authorize any interruption of production, yet the architect must surface disagreement among executives about who may declare a disaster and commit recovery funding. Which
- An architect has already run one tabletop exercise for the senior leadership team and a separate one for the operations team, because their responsibilities differ. Coordination across that reporting
- A tabletop exercise for a payment platform is being staffed. The design team needs one person whose sole duty during the event is to record what participants actually decide, so that the after action
- A tabletop exercise ended with every participant agreeing that the recovery procedure was clear, but the CIO now wants documented evidence that IT operations can be restored at the backup site. Which
- Which tabletop exercise document carries the observations recorded during the event and the recommendations for enhancing the exercised IT plan, developed after the facilitated debrief against evaluat
- Which class of weakness is a discussion-based exercise best suited to expose in an incident response plan, given that its participants only discuss roles, responsibilities and decisions and deploy no
- Modeling and simulation exercise behavior without requiring a live cutover
A simulation represents selected system or operational behavior in a controlled environment so scenarios and assumptions can be explored without production consequences. Its assurance is limited by model fidelity, input quality, and the differences between simulated and operational conditions.
4 questions test this
- NIST contingency planning guidance recommends that a moderate-impact system's contingency plan be exercised through a functional exercise including all plan points of contact; which element should the
- Which contingency plan testing enhancement does NIST prescribe when a recovery design's assumption about the standby data centre's capacity has so far been examined only in a modelled scenario, given
- An organization's annual contingency plan test covers only a fraction of its scenarios and cannot stress the system realistically; which enhancement to contingency plan testing does NIST guidance iden
- A simulated failover of an insurance platform completed inside the target window, but the simulation omitted a third-party identity provider that the production path depends on. Which limitation of si
- Manual functional review can examine logic that automated tests do not express
A reviewer can trace use cases, state transitions, trust decisions, and exception paths against requirements and threat scenarios before or without executing the implementation. This method is especially useful for architecture logic and missing behavior, but it cannot by itself prove runtime enforcement.
Trap Using document review as the sole evidence that a runtime control works
3 questions test this
- Which process is defined as confirmation, through the provision of objective evidence, that specified requirements have been fulfilled, as distinct from the process that confirms requirements for a sp
- The same engineering team that produced a payment gateway's design also performed the design review and declared it compliant. The authorising official doubts the result. Who should NIST guidance have
- Which review technique in NIST's technical testing and assessment guide judges whether security policies, architectures, requirements, standard operating procedures and interconnection agreements are
- Peer review uses relevant expertise to challenge design assumptions
Qualified peers can identify omitted viewpoints, inconsistent requirements, unsafe assumptions, and trade-offs that the original design team normalized. Review effectiveness depends on reviewer competence, scope, and access to the rationale and evidence, not merely attendance by another architect.
5 questions test this
- A program's toolchain automatically checks every design change against machine-readable rules derived from the security requirements, and the architect still commissions a review of the design by qual
- A design review that checks an architecture only against the approved security requirements list leaves one of the two review criteria in NIST's Secure Software Development Framework unaddressed. Whic
- A design review concludes that an embedded controller cannot meet a mandated cryptographic requirement, and every feasible design change has been costed and rejected by the program. The requirement it
- A design team submits its reference architecture for peer review and gives the reviewers the current diagrams and interface specifications only. The reviewers cannot establish why a shared administrat
- An architect commissions a peer review of a claims platform's design, and the delivery team nominates only the components it regards as security relevant. The shared identity and logging services are
- Assessment independence increases confidence in objective findings
An assessor independent of the design and implementation decisions is less exposed to self-review bias and conflicting incentives. Independence does not replace technical competence or adequate evidence, so an external label alone is not sufficient assurance.
Trap Choosing an external assessor solely because third-party status guarantees quality
9 questions test this
- SP 800-37 states that assessor independence during the continuous monitoring process brings a specific downstream benefit for ongoing authorization and reauthorization decisions, and organizations may
- A consultancy proposes to assess a bank's new payment architecture and, in the same engagement, to represent the bank before its regulator and argue the case for approving that architecture. Which imp
- A consultancy proposes to assess a bank's new payment architecture and, in the same engagement, to represent the bank before its regulator and argue the case for approving that architecture. Which imp
- SP 800-37 states that assessor independence during the continuous monitoring process brings a specific downstream benefit for ongoing authorization and reauthorization decisions, and organizations may
- A consultancy proposes to assess a bank's new payment architecture and, in the same engagement, to represent the bank before its regulator and argue the case for approving that architecture. Which imp
- SP 800-53's independent verification enhancement has two parts, and appointing an independent agent satisfies only the first of them. Which second requirement does a developer defeat by withholding de
- A claim that third-party status by itself guarantees the quality of an assessor's findings misreads the assessor-selection criteria set out in SP 800-53 and in the Risk Management Framework. Which fur
- A system owner wants to select an external assessment firm, set its scope, pay its fee from the delivery budget and receive its report directly. The authorizing official questions whether the result w
- A small agency must assess a moderate-impact system, but every person with the necessary technical knowledge sits inside the system owner's management chain, so no structurally independent assessor ca
- Strong assurance combines documentary, testimonial, and test evidence
Assessment methods commonly examine artifacts, interview responsible people, and test mechanisms or processes. Corroborating these sources distinguishes a documented design, an understood practice, and an operating control instead of inferring all three from one source.
5 questions test this
- A third-party test report can be recent, and entirely accurate about the deployment configuration it covers, and still fail one of the qualities NIST requires of assurance evidence once the design in
- A current compliance certificate can be offered as the only evidence that an encryption service protects tenant data, with no test results and no analysis standing behind the claim. Which named concep
- Assurance evidence for a safety-critical controller cannot always be gathered by exercising, measuring or watching the article itself under operational conditions before acceptance. Which route to ass
- SP 800-53A notes that an assessment procedure does not necessarily apply all three of the examine, interview and test methods to a control, and that the organization decides which of them to use. Whic
- Static analysis evidence for a lending platform shows a high density of findings dismissed as false positives, and the assurance value of that evidence must now be judged. Which course does SP 800-53
- Common Criteria assurance stays within the evaluated claims and scope
A Common Criteria result provides assurance only for the defined Target of Evaluation and the security claims and properties specified by its Security Target or claimed Protection Profile, as examined by the applicable evaluation methods and activities. It does not provide general assurance for unevaluated functions, configurations, or operating conditions.
- Manual code review is strongest where security depends on context and intent
Human review can reason about authorization logic, workflow abuse, trust assumptions, misuse of security functions, and requirement omissions that pattern-based tools may not understand. It is resource intensive, so threat models and criticality should focus review on high-risk code and interfaces.
6 questions test this
- An outsourced team delivers source code for a high-value settlement component. The concern is deliberately hidden logic rather than ordinary coding mistakes, and the code compiles cleanly under the or
- A development team reviews its own modules, and the same engineers who wrote the authorization helpers sign off on them. The architect wants review findings that an assessor will accept as evidence of
- A payments platform enforces per-role approval limits entirely in its own application code, and the approval matrix differs for every business unit. The architect must gain assurance that the implemen
- Pattern-based tooling reliably flags several weakness classes in first-party code, while others depend on knowledge of what the application is supposed to permit. Which weakness class is therefore the
- An architect authorizes three reviewer-days for the release of a claims system and selects two short modules that enforce entitlement rules. The reviewers ask what they should be looking for. Which in
- Manual code review capacity covers only a small fraction of a large codebase in each release cycle, so the review target list must be chosen deliberately rather than by convenience. Which input should
- Static analysis inspects source or compiled code without running it
Static analyzers examine code structure and data or control flows to identify weakness patterns before or independently of execution. They can cover large codebases consistently but require triage because findings can include false positives and context-dependent results.
Trap Dynamic analysis of application responses during execution
7 questions test this
- A quarterly release must be checked for weakness patterns across an entire 900,000-line monolith, but the staging environment can exercise only the customer-facing transaction paths. Which technique g
- A quarterly release must be checked for weakness patterns across an entire 900,000-line monolith, but the staging environment can exercise only the customer-facing transaction paths. Which technique g
- Two verification tools are being compared for a control-plane service: one reasons about the code as written, and the other supplies inputs to the deployed instance. Which property of the software doe
- A vendor supplies only signed executables for a component that the organization must assess before deployment. The architect needs weakness findings derived from the delivered artifact itself rather t
- A quarterly release must be checked for weakness patterns across an entire 900,000-line monolith, but the staging environment can exercise only the customer-facing transaction paths. Which technique g
- A first static analysis run over a large codebase returns several thousand warnings, and many of them describe conditions that a compensating control elsewhere in the application already blocks. Which
- Static analysis can be applied at several points in a delivery pipeline, and the point chosen changes both the feedback delay and the cost of fixing what it finds. Where does the organization gain the
- Dynamic analysis probes behavior in an executing system
Dynamic analysis supplies inputs to a running application and observes its behavior and responses. It can reveal runtime and configuration-dependent flaws but sees only the paths, states, and interfaces reached during testing.
Trap Assuming a clean dynamic scan proves unexecuted paths are secure
8 questions test this
- A gateway parses a binary telemetry protocol from thousands of field devices, and malformed frames from one faulty device once crashed the service. The architect wants evidence that the parser survive
- A gateway parses a binary telemetry protocol from thousands of field devices, and malformed frames from one faulty device once crashed the service. The architect wants evidence that the parser survive
- A gateway parses a binary telemetry protocol from thousands of field devices, and malformed frames from one faulty device once crashed the service. The architect wants evidence that the parser survive
- A quarterly vulnerability scan of an internet-facing platform reports only low-severity issues, yet the architect judges that several of them could be chained by an attacker who already holds a low-pr
- A dynamic security test suite runs against a deployed release and reports no findings, and that result will be quoted in the release's assurance evidence. Which additional measurement makes the scope
- A dynamic scan of a deployed application finishes with no findings, and a project manager reads that result as proof that the application contains no exploitable weaknesses. The architect must state w
- An application passes every verification activity in staging. Before release, the team reproduces the production reverse proxy, session termination, and debug-logging configuration in a preproduction
- A claims portal is deployed behind a gateway that rewrites its error responses, and integration testing has never inspected what those responses disclose to a caller. The architect wants evidence abou
- Software composition analysis evaluates included third-party components
SCA inventories libraries and other dependencies so teams can assess known vulnerabilities, versions, provenance, and other supply-chain concerns. It does not determine whether the organization's own business logic correctly enforces security requirements.
Trap Using SCA as a replacement for reviewing first-party authorization code
6 questions test this
- A platform passed a full dependency review at its initial release, and the same component set has shipped unchanged for a year. Which practice keeps the organization's view of that component set's ris
- A microservice estate pulls in hundreds of open-source libraries, and a newly published vulnerability in a widely used serialization library must be traced to every service that ships it. Which capabi
- Before a third-party component is approved for a regulated platform, the review board requires a machine-readable inventory of what the component itself contains, including its own dependencies and th
- A delivery team proposes to retire its authorization-code reviews on the grounds that its weekly dependency analysis has reported no vulnerable components for two quarters. The architect rejects the p
- A dependency report for a Java service lists only the libraries named in the project's build file, yet the running application loads many more archives than that file names. Which components must be a
- A component in a shipping platform passes every dependency scan the pipeline runs, but its upstream project has had no commits or releases for three years and no successor has been announced. Which at
- Third-party component assurance depends on its intended use
The SSDF calls for reviewing third-party components in the context of their expected use and repeating evaluation when that use changes substantially. A component acceptable in an isolated tool may carry different risk when placed on a critical trust boundary.
4 questions test this
- A third-party library was reviewed and approved a year ago for one specific system, and the approval record remains on file. Under the NIST Secure Software Development Framework, one later development
- A supplier delivers a compiled component for a settlement service, and the receiving architect can confirm neither its digital signature nor its provenance record. The component is still required for
- A microservice on a regulated payment path is assembled mostly from open-source libraries rather than from code written in-house. NIST guidance on developer verification sets the assurance standard th
- A payments organization applies the NIST Secure Software Development Framework to every reusable third-party component it approves. The review board must decide how much evaluation each candidate comp
- Threat models should direct code review and analysis toward critical paths
Mapped assets, trust boundaries, abuse cases, and attack paths identify where manual review, static analysis, dynamic analysis, fuzzing, and penetration testing provide the most value. Tool coverage metrics alone should not determine security test priorities.
6 questions test this
- One release covers both a tokenization service and an internal style-guide site, and the same test plan template is currently applied to each. The organization's threat model records far greater conse
- The SSDF calls for forms of risk modeling during design so that security risk to the software can be assessed. Before analysis effort can be targeted, reviewers need to know which parts of the softwar
- One release covers both a tokenization service and an internal style-guide site, and the same test plan template is currently applied to each. The organization's threat model records far greater conse
- A gateway service accepts several externally supplied message formats, and the architect can fund fuzz testing of only one parser in this release. The team maintains a current threat model of the gate
- Functional acceptance tests for a claims portal all pass, but they exercise only the behaviour that the specification describes. Security test cases are now needed that represent an attacker deliberat
- An architect has one week of specialist security testing to allocate across three services in a payments estate, and a current threat model exists for all three. Adding testing capacity this quarter i
- Code-analysis findings require triage, remediation, and verification
Developer verification records discovered issues, determines their validity and priority, routes remediation into the development workflow, and verifies the fix. Counting tool alerts without disposition and regression evidence is not a completed review process.
Trap Using the raw scanner report as final assurance evidence
4 questions test this
- A release package offers the raw output of its static analysis run as the application security evidence for a regulated service. The assessor rejects the package, and the architect must state what tha
- A quarterly report shows that most static analysis findings were marked as false positives and closed with no code change, and that closing rate is being read as evidence of high code quality. What do
- The same missing-authorization defect pattern has been reported by three separate code reviews of different services over two quarters, and each instance was corrected on its own. New code keeps repro
- A session-fixation defect that was found and fixed in last year's review has reappeared in the current release of the same service. One change to the verification process itself keeps that defect from
- Secure code review verifies control presence, operation, and placement
Secure code review audits application source to verify that security and logical controls are present, operate as intended, and are invoked in the right places. Its objective is to discover security defects and potentially identify solutions.
Trap Successful execution of each control in isolation proves that the control is invoked at every required point.
4 questions test this
- An assessor asks the architect for evidence that the documented role-permission scheme of a claims system is the one the application actually enforces. Automated analysis of the codebase has already r
- A secure code review is expected to return more than a list of defects: for each finding it also yields something the development team can act on directly, which OWASP identifies as part of the review
- Unit tests show that an authorization helper returns the correct decision for every role it is given, and the architect still commissions a source review of the services that depend on it. What does t
- A financial application has completed a thorough secure code review, and a penetration test of the same application is scheduled immediately afterwards. OWASP's code review guidance states what the te
Infrastructure and System Security Architecture
Identify Infrastructure and System Security Requirements
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Architect Infrastructure and System Security
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Architect Infrastructure and System Cryptographic Solutions
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- The cryptographic mechanism must match the required security service
Select encryption for confidentiality, a MAC for symmetric integrity and source authentication, and digital signatures when public verification and signer evidence are required. No single primitive automatically supplies every security property.
5 questions test this
- A messaging design must conceal the content of each transaction record and let the receiver detect any tampering with that record in transit. The architect wants one mechanism to deliver both properti
- A clearing house protects settlement messages with a message authentication code computed under a key that both participants hold. Auditors ask whether the design can resolve a dispute in which one pa
- A supplier portal accepts purchase commitments from external buyers. The design must let an independent arbitrator confirm which buyer approved a given order, even after that buyer denies having appro
- Two internal services already share a symmetric key. The architecture must let the receiver detect unauthorized modification of each message and confirm which service sent it. Proof of origin usable b
- A messaging design must conceal the content of each transaction record and let the receiver detect any tampering with that record in transit. The architect wants one mechanism to deliver both properti
- Symmetric and asymmetric cryptography solve different architectural problems
Symmetric algorithms efficiently protect bulk data but require communicating parties to share secret keying material. Asymmetric techniques support signatures or key establishment without a pre-shared pairwise secret but impose different trust and computational costs.
11 questions test this
- A programme proposes a symmetric-only design in which every pair of member organizations holds its own distinct encryption key. Leadership asks what will constrain the design as the membership grows f
- Two enterprises with no prior relationship and no shared secret must set up protected communications across an untrusted network within a day, and manual courier distribution of keying material is una
- A programme proposes a symmetric-only design in which every pair of member organizations holds its own distinct encryption key. Leadership asks what will constrain the design as the membership grows f
- Two enterprises with no prior relationship and no shared secret must set up protected communications across an untrusted network within a day, and manual courier distribution of keying material is una
- A replication link carries several terabytes of records between two data centers every night, and the architect must protect the payload without making the cryptography the throughput bottleneck. Whic
- A design distributes each service's public key as an email attachment. A reviewer objects that a recipient cannot tell whether a received public key really belongs to the named service. Which addition
- A programme proposes a symmetric-only design in which every pair of member organizations holds its own distinct encryption key. Leadership asks what will constrain the design as the membership grows f
- Two organizations must establish a shared secret for a new interconnect. Policy states that the secret must depend on information contributed by both parties, so that neither party alone determines it
- Two enterprises with no prior relationship and no shared secret must set up protected communications across an untrusted network within a day, and manual courier distribution of keying material is una
- An enterprise wants a central service that issues session keys on demand to two internal applications that share no key with each other. Each application already shares a long-term key with that centr
- An archive service encrypts each large file with a freshly generated symmetric key, then protects that symmetric key with the recipient's public key before sending both. The architect must name this c
- A cryptographic hash does not provide confidentiality
A hash produces a fixed-length digest intended to make reversal and collisions infeasible; it does not use a decryption key to recover plaintext. Use it for integrity constructions and fingerprints, not to hide predictable sensitive values by itself.
9 questions test this
- A messaging design must conceal the content of each transaction record and let the receiver detect any tampering with that record in transit. The architect wants one mechanism to deliver both properti
- A data-protection design replaces each customer reference with a pseudonym in the analytics store. Support staff must still be able to recover the original reference through a controlled process. Whic
- An ingest service stores the digest of every uploaded document so that a later upload of the same content can be recognized without keeping a second copy. Which property of the hash function makes thi
- Two internal services already share a symmetric key. The architecture must let the receiver detect unauthorized modification of each message and confirm which service sent it. Proof of origin usable b
- A privacy design replaces each customer's national identifier with the digest of that identifier and claims the digest keeps the identifier confidential. The identifier follows a short, predictable fo
- Two partner organizations pseudonymize the same customer identifier with the same unkeyed digest function and then exchange datasets for joint analysis. The architect is asked to state the residual pr
- A team argues that storing only the digest of each personal record satisfies a regulatory requirement to encrypt that data at rest. The architect must base the review on how a digest differs from a ci
- A distribution design publishes each firmware image beside an unprotected digest so that recipients can detect corruption. A reviewer notes that an attacker who can alter the image can also post a mat
- A messaging design must conceal the content of each transaction record and let the receiver detect any tampering with that record in transit. The architect wants one mechanism to deliver both properti
- Cryptographic module validation applies to a defined module boundary
FIPS 140-3 validation provides assurance about a cryptographic module's specified implementation and boundary. It does not certify the security of the entire application, key-management process, protocol design, or surrounding system.
7 questions test this
- An integrator must determine exactly which components lie inside a software module's cryptographic boundary and which services the module offers when it runs in its approved mode. Neither fact is visi
- An integrator must determine exactly which components lie inside a software module's cryptographic boundary and which services the module offers when it runs in its approved mode. Neither fact is visi
- An integrator must determine exactly which components lie inside a software module's cryptographic boundary and which services the module offers when it runs in its approved mode. Neither fact is visi
- A procurement standard demands two separate pieces of evidence for a cryptographic component: that it uses approved cryptography, and information about the company that builds and controls it. The bid
- An architect must choose between two validated modules that implement identical approved algorithms, for deployment in unattended roadside cabinets where an adversary can handle and open the enclosure
- Installers deploy a validated hardware module in an unattended kiosk without following the configuration instructions in the module's non-proprietary security policy, and the module ends up offering s
- A vendor markets a storage appliance as FIPS 140-3 validated, and a certificate does exist for the cryptographic library the appliance embeds. The appliance ships with a firmware release later than th
- Implementation attacks can defeat sound algorithms
Threat models should include side channels, weak randomness, protocol misuse, key exposure, fault attacks, and insecure error handling in addition to mathematical attacks. Selecting an approved algorithm does not compensate for an implementation that leaks keys.
7 questions test this
- Smart meters installed on customer premises sign their readings with an approved algorithm. A laboratory recovers the signing key by correlating the power the meter draws with the operations it is per
- A payment terminal checks a signature over its firmware at boot before handing control to it. Researchers induce brief voltage glitches on the power rail during that check and make the terminal accept
- A payment terminal checks a signature over its firmware at boot before handing control to it. Researchers induce brief voltage glitches on the power rail during that check and make the terminal accept
- A review of a service that verifies message authentication codes finds that the comparison stops as soon as the first differing byte is reached, and an attacker on the network can observe how quickly
- A programme replaces one cryptographic library with a different implementation of the same approved algorithms and key sizes, and the schedule treats the change as like-for-like because the approval s
- Smart meters installed on customer premises sign their readings with an approved algorithm. A laboratory recovers the signing key by correlating the power the meter draws with the operations it is per
- A service decrypts submitted tokens and answers with one message when the decrypted structure is malformed and a different message when the integrity check fails. An assessor uses that difference to r
- Cryptographic lifecycle planning includes standards transition
Inventory algorithms, keys, certificates, protocols, dependencies, and protected-data lifetimes so systems can migrate before current protection becomes inadequate. Long-lived data may require transition earlier than short-lived data because attackers can retain ciphertext for later decryption.
5 questions test this
- A migration programme lists the algorithms configured in the applications its own teams build and declares discovery complete. The architect points out that a large part of the estate's cryptography s
- A partner link carries records that must stay confidential for decades, and the key-establishment algorithm protecting it is scheduled for withdrawal several years from now. The programme proposes to
- A programme replaces the signature algorithm used by a workforce authentication system, and every party that presents or accepts those credentials has to move with it. The architect is asked what will
- Guidance announces that an algorithm the organisation relies on will no longer provide adequate protection after a published date. The operations team answers by shortening cryptoperiods and rekeying
- A utility procures controllers whose firmware-verification code is fixed in read-only memory at manufacture, and the fleet is expected to remain in the field for decades. The procurement specification
- The FIPS 140-3 level must fit the application and environment
FIPS 140-3 defines four increasing qualitative module-security levels, not one universal assurance target. Select a validated module level whose protections fit the application's security requirements, data sensitivity, operating environment, and exposure rather than choosing a level solely because it is higher.
7 questions test this
- A cryptographic module already deployed for an internal scheduling tool will be reused unchanged to protect regulated payment records. The programme records no cryptographic action for the change, bec
- An architect must choose between two validated cryptographic modules for equipment installed in unstaffed branch offices, where physical protection carries most of the design risk. The procurement sum
- An architect is drafting the cryptographic requirement for a claims-processing platform, and the procurement standard must name the FIPS 140-3 security level that the embedded module has to hold. The
- Two key stores in the same enterprise hold keying material for different systems: one protects the patient identifiers in a clinical records index, and the other protects a staff canteen menu service.
- A design team rejects a module validated at the standard's lowest security level, arguing that such a validation demonstrates nothing at all about how the module protects keying material. The architec
- A programme is shortlisting cryptographic modules from several suppliers and cannot commission laboratory testing of its own. Each candidate carries a validation issued under the Cryptographic Module
- An enterprise is deploying validated cryptographic modules into unattended field terminals, and each validation entry states the security level the module met under test. The architecture document mus
- At-rest encryption primarily protects stored representations
Disk, volume, file, object, or database encryption can protect data when storage media or copies are obtained without authorization. It does not protect plaintext after an authorized process has unlocked and read the data.
3 questions test this
- A hospital group is retiring self-encrypting drives from a storage array and proposes cryptographic erase as the purge method so the units can leave the site the same week. Which condition must the ar
- A laptop standard credits full disk encryption with pre-boot authentication as the control that satisfies the organization's data-protection requirement. The architect documents the residual risk by s
- Which storage encryption approach limits plaintext exposure to the moment a user explicitly authenticates to an individual protected item, so that unopened items stay encrypted while the workstation i
- Transit protection should authenticate endpoints as well as encrypt traffic
Use a protocol such as properly authenticated TLS or IPsec when data needs confidentiality and integrity over an untrusted path. Encryption without peer authentication can establish a protected channel to an attacker.
5 questions test this
- A proposal secures a partner data feed with unauthenticated Diffie-Hellman key agreement, arguing that the payload is encrypted either way. The reviewing architect names the primary risk this creates.
- Two partner organizations expose machine-to-machine APIs to each other across the public internet. Each side must be able to prove during channel establishment which counterpart it is talking to. Whic
- Two application servers in different zones of a data centre exchange sensitive records. Neither application can be modified to add its own protection, and the traffic must be authenticated and encrypt
- Which protection keeps a business document readable and verifiable only by its originator and final recipient when it is relayed through a chain of brokers, each of which is itself an endpoint of the
- Which client-side verification step establishes that the certificate presented during a TLS handshake actually belongs to the particular service the client set out to reach, rather than to another wor
- In-use protection narrows plaintext exposure during computation
Trusted execution environments and secure enclaves can isolate code and data while they are processed and can support attestation of execution state. They reduce exposure to other platform layers but still depend on correct code, trusted roots, and sound key release policy.
6 questions test this
- Which capability lets a relying party obtain cryptographic evidence that the code and platform actually executing a remote workload match the configuration the party approved, before it releases regul
- A data-sharing consortium admits a partner workload only after a verifier appraises the signed attestation evidence the workload produces. To cut round trips, the operator proposes storing that eviden
- Which design responsibility remains with the development team after an application is moved into a trusted execution environment, given that the environment protects the code and data it holds from in
- A regulated tenant moving to a public cloud will not accept the provider's hypervisor inside its trust boundary, and its off-the-shelf applications cannot be rebuilt or re-linked. Which confidential-c
- A tenant's workload runs on shared cloud hosts. The architect must reduce the risk that another workload or a compromised platform layer reads the tenant's data out of system memory while it is being
- A confidential-computing design must ensure the key protecting a customer's dataset becomes available to an enclave only when the enclave's reported state matches the approved configuration. Which key
- End-to-end encryption avoids plaintext at intermediaries
With link encryption, each network hop may decrypt and re-encrypt data, so intermediaries can see plaintext. End-to-end encryption keeps content protected between communicating endpoints, although intermediaries may still observe routing metadata.
Trap Hop-by-hop link encryption
6 questions test this
- A finance division sends transaction files across a leased circuit that the carrier already protects with link encryption. The architect still requires protection applied by the sending application an
- Which cryptographic arrangement keeps message content unreadable to a carrier's intermediate nodes and at the same time conceals the outer addressing of every frame from anyone monitoring the leased s
- A carrier protects a multi-node backbone with link encryption, and every intermediate node decrypts and re-encrypts each frame it forwards. The architect must explain to the risk committee why those n
- Which architectural consequence follows when a clearing house that relays trade messages protected between partner applications is permitted to read and rewrite the body of each message before forward
- Which characteristic of traffic protected by end-to-end encryption between two hosts stays available in real time to an adversary who is positioned on an intermediate network segment and can observe e
- A retailer terminates every customer session at its perimeter load balancer and then forwards the requests to application servers over the internal network with no protection applied. The architect la
- Authenticated encryption protects confidentiality and detects modification
Select an approved authenticated-encryption construction when ciphertext confidentiality and integrity are both required. Encryption without an integrity mechanism can permit undetected manipulation even when plaintext remains unreadable.
6 questions test this
- A development team proposes to encrypt records with a block cipher mode and to protect their integrity with a separate message authentication computation, rather than selecting an approved authenticat
- A team places full customer records in the associated-data input of an authenticated-encryption operation so that a downstream service can index them without holding any key, and the architect rejects
- A payment platform encrypts each message with a confidentiality-only mode before placing it on a queue that a third party operates, and nothing verifies the ciphertext when the message is read back. W
- Which assurance must a design supply before AES in Galois/Counter Mode may be deployed across an embedded fleet whose devices cannot reliably preserve counter state across restarts, power failures and
- Which handling does published guidance require for received packets whose authentication tags fail verification, so that the receiver's response cannot be used by an attacker to learn the integrity re
- A team wants to assemble its own combination of an encryption mode and a message authentication computation instead of selecting an approved authenticated-encryption mode. The architect records the pr
- Envelope encryption separates data keys from key-encryption keys
Encrypt data with a data-encryption key and protect that key under a separately managed key-encryption key. This supports scalable data protection and centralized rotation of the wrapping layer without using one long-term key directly for all bulk data.
6 questions test this
- Which statement describes what must happen to a key-encryption key that has been retired from further wrapping operations once its originator-usage period ends, while archived data keys that were wrap
- Which consideration decides whether one data-encryption key should protect an entire document repository or whether each document should instead receive its own key that is wrapped under a shared key-
- A central key-management service wraps and stores the long-lived data-encryption keys of an enterprise archive under a single key-encryption key. Which requirement does published guidance place on tha
- A shared hosting design keeps the key-encryption key and the wrapped data-encryption keys in the same application database, because the platform offers no separate key store. The architect records the
- A multi-tenant platform currently wraps every tenant's data keys under one key-encryption key that the provider holds. The architect proposes a change that limits how far the disclosure of a single wr
- A design encrypts each stored object under its own data-encryption key and keeps the wrapped form of that key in the same bucket as the object it protects. The architect states the condition that make
- Digital signatures authenticate data but do not conceal it
A valid signature can provide integrity, origin evidence, and public verification according to the certificate and key trust model. Encrypt separately when the signed content also requires confidentiality.
6 questions test this
- A programme office exchanges S/MIME messages with a partner over public relay servers. The design must keep both the message body and the identity of the individual staff signer hidden from every rela
- An email gateway encrypts each outbound message for the recipient organisation and then signs the resulting ciphertext with the gateway's own certificate. The receiving partner verifies that signature
- An agency must publish a policy record set that its authoring system has already signed, and personal data must be removed from the released version. A first attempt fails verification at the public s
- A relying party receives a contract file whose signature verifies mathematically against a public key supplied inside the same file. No certificate from a known issuer accompanies it. Which additional
- A regulated firm stores its transaction records with an outsourced archive operator. Each record is digitally signed by the originating system before it is transferred, and the operator stores the rec
- A programme office exchanges S/MIME messages with a partner over public relay servers. The design must keep both the message body and the identity of the individual staff signer hidden from every rela
- TLS 1.3 forward secrecy does not make 0-RTT replay-safe
TLS 1.3 (EC)DHE key exchanges provide forward secrecy, while PSK-only use can forfeit it. Its 0-RTT mode reduces connection latency but lacks inherent replay protection, so allow early data only for operations safe to replay and require application-level duplicate handling where applicable.
- Key generation requires approved unpredictable randomness
Generate keys with an approved random bit generator and enough entropy for the intended algorithm and strength. A long key produced from predictable input remains weak regardless of its nominal bit length.
5 questions test this
- A team plans to raise the assurance of its stored records by issuing longer symmetric keys, while continuing to seed those keys from the same generator the platform uses today. Which factor determines
- A symmetric key that protects a records archive has been disclosed to an unauthorised party, and the architecture must state how its replacement will be produced before the archive is re-encrypted und
- A design review of a payment platform finds that its data-encryption keys are produced by a software routine seeded from the host clock and the current process identifier, even though every key is iss
- Four business units must share one symmetric key, and none of them operates a key-generation capability of its own. The architecture team needs a source for that key which every unit is prepared to re
- An architect is writing the cryptographic standard for a new platform and must state where symmetric keys are produced, so that the random value behind each key never exists outside the protected boun
In key agreement, both parties contribute information used to derive keying material rather than one party selecting and sending the final secret key. Bare Diffie-Hellman needs authentication from the surrounding protocol to resist man-in-the-middle attacks.
Trap Unauthenticated Diffie-Hellman
7 questions test this
- A sender obtains the intended receiver's public key, generates a symmetric key inside its own module, encrypts that symmetric key under the receiver's public key, and sends the resulting ciphertext ke
- Two newly built sites are to establish keys automatically once they are running, but on the day they are commissioned they hold no secret in common and no certificate infrastructure yet reaches either
- Two data centres exchange bulk records every night. Their key-establishment scheme has each side contribute only its own certified long-term key pair, and no short-term value is introduced by either p
- An approved key-agreement scheme first computes a shared secret value from the two parties' contributions, and the architecture must state how the traffic-protection keys are obtained from that value.
- Two peers complete an approved key-agreement transaction and each derives keying material from the resulting shared secret, but neither has yet received any evidence that the other actually holds iden
- An approved key-establishment procedure produces secret keying material as a function of information contributed by both participants, so that neither of them can predetermine the resulting value inde
- A regulator requires that recorded sessions between a bank's public service and its customers stay protected even if the service's long-term private key is disclosed years afterwards. The service term
- Key transport securely delivers a key selected by one party
In key transport, one party generates or obtains keying material and protects it for delivery to another party. This differs from key agreement, in which the resulting shared secret is derived from contributions by both sides.
7 questions test this
- A sender obtains the intended receiver's public key, generates a symmetric key inside its own module, encrypts that symmetric key under the receiver's public key, and sends the resulting ciphertext ke
- Two newly built sites are to establish keys automatically once they are running, but on the day they are commissioned they hold no secret in common and no certificate infrastructure yet reaches either
- A data-encryption key has to be moved across an untrusted path to another cryptographic module, and the receiving module must be able to detect any alteration of the key in transit as well as keep its
- An architect reviews a proposal in which a single key pair would serve both to receive protected session keys sent by trading partners and to produce the organisation's code-signing signatures. Which
- A symmetric key must be loaded by hand into a cryptographic module at a remote site. The organisation requires that no member of staff involved in the process can learn the whole key value at any stag
- An approved key-establishment procedure produces secret keying material as a function of information contributed by both participants, so that neither of them can predetermine the resulting value inde
- In a large enterprise a central service creates each session key and hands both communicating subscribers their own protected copy of it, and neither subscriber contributes any keying material of its
- Key distribution must protect both key secrecy and source authenticity
Secret and private keying material needs confidentiality during distribution, while all key associations need integrity and authentic binding to the intended party and purpose. A confidential channel to an unauthenticated recipient can deliver a key securely to the wrong party.
6 questions test this
- A distribution package carries an organisation's public signature-verification keys together with the domain parameters those keys are used with. Key-management guidance names one protection that shal
- Key-management guidance requires confidentiality protection for only part of the material that travels in a key distribution, while integrity protection applies to all of it. Which item of that materi
- A key-distribution scheme wraps every symmetric key under an approved algorithm and moves it over a channel offering strong confidentiality, yet nothing in the scheme establishes which party is receiv
- A key-processing facility produces human-readable key material that has to reach three branch sites by hand rather than over a network, and the organisation does not intend to encrypt it before it lea
- An organisation is deciding how key material will reach the cloud key-management service that protects its records. One team proposes generating keys in the organisation's own hardware and importing t
- A certification authority binds a subject name to a public key that arrived in an enrolment request. A reviewer warns that, without one further check, an attacker could obtain a certificate for a publ
- A cryptoperiod limits how long a key is authorized for use
Set cryptoperiods according to algorithm strength, key type, data volume, exposure, operational environment, and consequences of compromise. Rotation schedules should follow risk and purpose rather than use one arbitrary interval for every key.
7 questions test this
- A single symmetric key protects an extremely high-rate telemetry stream, and the volume of data encrypted under that one key grows by orders of magnitude each month. The algorithm and its mode of oper
- A symmetric key is no longer used to apply protection to new entries in a records archive, but entries protected under it years earlier must still be decrypted on demand. One part of that key's crypto
- Remote sites hold keys that can be changed only by an engineer travelling to each site with a key loader. An improvement programme proposes cutting the cryptoperiod so that every key changes monthly,
- One symmetric key has been loaded into several thousand field devices, and two operations centres each keep a recovery copy of it for continuity. A reviewer asks the architect to justify this key's cr
- Cryptoperiods are generally made longer for keys that protect stored data than for keys that protect communication exchanges, even where both keys use the same algorithm and the same key length. Which
- The cryptoperiod of a key has ended. The key material is unchanged, it remains inside its cryptographic module, and no compromise has been reported, yet legitimate entities may no longer use it to app
- A financial services firm applies one twelve-month rotation interval to every cryptographic key it holds, from short-lived session keys through to the key protecting a decade of archived statements. T
- Keys should be separated by cryptographic purpose
Do not use one key pair interchangeably for signing, encryption, authentication, and key establishment unless the approved scheme explicitly permits the combination. Purpose separation limits compromise impact and supports distinct lifecycle treatment.
7 questions test this
- A certification authority design proposes one private key to sign issued certificates and a second, separate private key to sign the revocation lists. The PKIX profile permits either arrangement and n
- A scheme uses one symmetric key to encrypt a record and then, in a separate operation, to compute a message authentication code over that same record. Guidance gives a reason why one key should not se
- A platform team protects eight unrelated applications with one cloud key-management service, and has given every one of those applications the same root key-encryption key. The security architect must
- A programme sponsor questions the cost of issuing every subscriber one key pair for signing and a second pair for key establishment, and asks the architect for the reason published guidance gives for
- Key-management guidance normally forbids a static private key-establishment key from generating digital signatures, because a key should serve a single cryptographic purpose. The same guidance names o
- An enterprise wants every private key its staff hold to be recoverable by the organisation, so that no protected material is ever lost when a person leaves. The architect reviews the proposal against
- Published guidance says a single key shall be used for only one purpose, then adds that this does not preclude one key where a single process provides more than one security service, and offers the di
- A certificate binds a public key to a named subject under an issuer's policy
A relying party must validate the certification path, validity period, intended key use, name, and revocation status before relying on the binding. The certificate does not protect the subject's private key from compromise.
4 questions test this
- After an acquisition, a manufacturer's root authority issues a CA certificate to the subsidiary's existing authority, whose certificates assert the subsidiary's own policy identifier, while the parent
- A design treats a signature that verifies under a currently valid certificate as evidence that the named subject personally approved a payment instruction of high value. Which property must hold for t
- A payments platform will trust a large hierarchy that certifies subscribers at several assurance levels, and its regulator requires the platform to refuse any certificate issued below a stated level.
- A defence agency cross-certifies a contractor's certification authority so that agency systems will accept contractor-issued certificates, and the agency's risk owner insists that authority must never
- An HSM keeps sensitive key operations inside a protected boundary
Use a hardware security module when keys must be generated, stored, and used under tamper-resistant controls with tightly governed interfaces. An HSM reduces key exposure but does not decide whether callers are properly authorized unless the surrounding design enforces that policy.
5 questions test this
- A cryptographic module is being withdrawn from service and returned to the vendor. The architecture must ensure that no secret or private key held inside the module can be recovered afterwards by phys
- An architect must protect symmetric keys that are held outside the cryptographic module, on general-purpose storage. Both the confidentiality and the integrity of the stored keys must be preserved by
- An architect is completing a system security design and must name the publication whose requirements the chosen cryptographic module has to satisfy across areas such as physical security, roles and se
- During a design review, an architect is asked to name the construct that, for a cryptographic module, is the explicitly defined continuous perimeter establishing the module's physical bounds and conta
- A payment platform has moved its transaction signing keys into a validated hardware security module. Any service account that can reach the module's client interface is now able to submit a signing re
- Key recovery is appropriate for decryption keys but hazardous for signing keys
Archive or escrow decryption keys when authorized recovery of protected data is a business requirement. Private signature keys generally should not be escrowed because another holder could create signatures as the subscriber and undermine signer accountability.
Trap Signature-key escrow
5 questions test this
- A public key infrastructure must let the organization recover encrypted mail when a user is unavailable for an extended period. It must also keep each user solely accountable for every signature made
- An organization must be able to read files that departing employees encrypted for themselves. The architect will retain a recoverable copy of exactly one key type from each employee's key set. Which k
- A central facility currently generates and distributes signing key pairs for every subscriber. Legal counsel now requires that individual subscribers be held accountable for their own signatures. Whic
- A retention rule obliges an insurer to read policy records that were encrypted years ago, well after the cryptoperiod of the keys that protected them has ended. The architect must choose where those k
- An architect is defining what the enterprise key archive will retain so that protected data stays recoverable after cryptoperiods end. One key type is excluded by NIST key-management guidance from arc
- Key backup trades recovery availability against additional exposure
Protect backup key copies at least as strongly as operational copies, control their restoration, and inventory their locations. Extra copies can prevent permanent data loss but also enlarge the set of targets that can compromise protected data.
8 questions test this
- An enterprise plans to hold wrapped copies of its production keys on a lower-cost storage tier that a different operations team owns and administers, separately from the operational key store. Which r
- A design board must decide, key type by key type, whether the enterprise will keep recoverable copies of its keying material at all, rather than re-establishing keys after a loss. Which trade-off does
- An architect is specifying how the confidentiality of the key material held in the enterprise key archive will be protected while it sits in long-term storage, separately from the operational systems
- An organization holds backup copies of its long-term keys across several facilities and third-party services. No single record shows which keys exist, who sponsors each of them, or where every copy is
- An architect reviews a proposal to back up every symmetric key used by an internal messaging system. The peers can establish replacement keys automatically within seconds whenever a key is lost or cor
- An organization will retire a records system by destroying the keys that encrypt its archives, so that the stored ciphertext can no longer be read. Those same keys were replicated to a disaster-recove
- A key-management system lets any storage administrator pull a backed-up key out of the backup store and reload it into a live service. The architect is now writing the security requirements for the ba
- An enterprise plans to hold wrapped copies of its production keys on a lower-cost storage tier that a different operations team owns and administers, separately from the operational key store. Which r
- Certificate revocation stops future reliance but does not erase past exposure
Publish and check revocation status promptly when a private key or binding is no longer trustworthy. Revocation does not recover a compromised private key, decrypt previously captured ciphertext, or invalidate every historical signature automatically.
8 questions test this
- An enterprise revokes a subscriber's public key because the subscriber's registered mail address changed. The private key is not suspected of compromise, and more than a year remains in the key's cryp
- A relying party receives an Online Certificate Status Protocol response of good for a certificate presented during a session handshake. The design documentation must state precisely what that response
- A certification authority's private signing key has been disclosed. Investigators have already established that the attacker can mint fraudulent certificates under that authority, and relying parties
- A certification authority learns on 20 March that a subscriber's private key was disclosed on 6 March, and the certificate is revoked that day. Relying parties need to see when the key actually stoppe
- A private signature key is found to have been compromised on day 15 of its cryptoperiod. A receiver holds a message signed on day 1 that has stayed under continuous physical protection since it arrive
- An adversary has archived ciphertext that partner systems encrypted to a subscriber's public key. The subscriber's private key was disclosed last week, and the certification authority revoked the cert
- A certification authority revokes a subscriber's certificate because the subscriber has left the organization. Nothing suggests that the private signature key was disclosed. Relying parties hold docum
- Two organizations protect a batch file transfer with a shared symmetric key that they exchanged directly and registered with no key-management infrastructure. One party decides to terminate the key's
- Key compromise response requires more than scheduled rotation
Stop use, revoke or distrust affected credentials, generate replacement keys, distribute new trust, assess exposed data, and re-protect information where required. Waiting for the normal cryptoperiod to expire leaves a known compromised key active.
8 questions test this
- One symmetric key protects message traffic among twelve business units. The key store of a single unit is breached and the key is exposed. Managers propose replacing the key for that unit alone and re
- Key-management guidance assigns responsibility for reporting a possible key compromise, and an enterprise procedure is being written to reflect that assignment. The procedure will be audited against t
- A key that encrypted seven years of customer records is compromised. It has been revoked, a replacement key is in service, and all new records are protected under the new key. Retention rules require
- A certification authority's private signing key has been disclosed. Investigators have already established that the attacker can mint fraudulent certificates under that authority, and relying parties
- After a key compromise, an enterprise revokes the key, generates a replacement, and notifies the relying parties it knows about. The architect must add the plan element that keeps systems still holdin
- A private signature key is found to have been compromised on day 15 of its cryptoperiod. A receiver holds a message signed on day 1 that has stayed under continuous physical protection since it arrive
- An adversary has archived ciphertext that partner systems encrypted to a subscriber's public key. The subscriber's private key was disclosed last week, and the certification authority revoked the cert
- An archive service uses one symmetric data-encryption key, and that key is confirmed compromised. Replacement keys cannot be provisioned until next week, and business owners want to know what the serv
- Cryptographic erasure renders encrypted data inaccessible by destroying keys
Crypto erase is effective only when strong encryption covered the target data and all usable copies of the relevant keys can be destroyed. Surviving key backups or plaintext copies defeat the sanitization claim.
5 questions test this
- A storage team performs cryptographic erase by sanitizing the wrapped copy of a drive's media-encryption key. During normal operation that drive had unwrapped the key into working memory and written i
- A managed service escrows the media-encryption key of every laptop in a key-management server that another team administers. The storage team plans to rely on cryptographic erase when the laptops are
- Self-encrypting drives will be redeployed from a sensitive system to another internal system, and cryptographic erase is to be applied first. Recovery of the target data must remain infeasible under s
- Cryptographic erase has been completed on a batch of solid-state drives that will be returned at the end of a lease. The meaning of verification for that operation must be settled before the drives le
- A retention rule will require an enterprise to render specific records held in a provider's object storage service unrecoverable at a fixed date. The provider keeps replicas of those records across po
- Split knowledge prevents one custodian from knowing the complete secret
Divide sensitive key material or activation information so no single participant possesses the whole value. Merely requiring two approvals while one administrator still knows and can copy the full key is dual authorization, not split knowledge.
6 questions test this
- Custodians bring their key components to a console, an operator types both into a spreadsheet to combine them, and the resulting value is then entered into the cryptographic module. The components the
- A key-loading procedure requires two administrators to be present and to sign the log before the master key is entered. The senior administrator reads the full key value aloud from a sealed printout w
- An assessor must test whether an enterprise's claim of divided key custody is real rather than merely procedural. Both custodians confirm in interview that neither of them can produce the key alone, a
- A design forms a master key by joining two components end to end, one component held by each of two custodians. Each custodian therefore holds a known, fixed portion of the finished key value, and bot
- Two custodians hold separate components of a signing key, and the design is described as protected because neither can reconstruct the key alone. Once the key has been loaded and is active inside the
- A design nominates the duty shift manager as the second party for every cryptographic key operation. The manager has no cryptographic training and approves each request on the strength of the requeste
- Dual control requires two authorized actors for a sensitive key operation
Use dual control when generation, activation, recovery, export, or destruction must not be completed by one person acting alone. It can be combined with split knowledge, but the two controls address action authority and secret possession differently.
11 questions test this
- A cryptographic key-management design is being assessed against published guidance, and the assessor asks how the enterprise decided where two-party authorization applies. The design records only a ge
- A utility plans to place every cryptographic key operation in its substation control system under two-party authorization, including the operations field staff perform while restoring supply after a f
- A utility plans to place every cryptographic key operation in its substation control system under two-party authorization, including the operations field staff perform while restoring supply after a f
- A utility plans to place every cryptographic key operation in its substation control system under two-party authorization, including the operations field staff perform while restoring supply after a f
- A key-loading procedure requires two administrators to be present and to sign the log before the master key is entered. The senior administrator reads the full key value aloud from a sealed printout w
- The same two custodians have jointly authorized every key-recovery operation for three years, and both sit in one small team reporting to a single manager. An assessor questions the assumption on whic
- A cryptographic key-management design is being assessed against published guidance, and the assessor asks how the enterprise decided where two-party authorization applies. The design records only a ge
- Two custodians hold separate components of a signing key, and the design is described as protected because neither can reconstruct the key alone. Once the key has been loaded and is active inside the
- A hardware key store is configured so that one operator's activation credential is enough to bring the signing keys into a usable state after a restart. The architecture states that no individual may
- A design nominates the duty shift manager as the second party for every cryptographic key operation. The manager has no cryptographic training and approves each request on the strength of the requeste
- An enterprise policy states that two named officers must agree before any key-recovery operation is performed. The key-management system, however, will execute a recovery for whichever officer submits
Identity and Access Management (IAM) Architecture
Architect the identity lifecycle
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Architect identity authentication
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Multifactor authentication combines independent factor categories
Two secrets that are both known, or two devices that are both possessed, do not become multifactor merely because two checks occur. MFA requires evidence from distinct categories such as knowledge, possession, and inherence.
Trap Counting a password and a security question as two factors
3 questions test this
- An enterprise stores both the workforce password and the seed for the one-time-password application in the same endpoint password manager, so a single endpoint compromise yields both. Which multifacto
- A multi-factor one-time-password token can be configured to accept its PIN once and then release codes for the rest of the workday without further entry. NIST digital identity guidance rules out that
- NIST digital identity guidance distinguishes a password that is sent to a verifier over a protected channel from a password that is verified locally inside a multi-factor authenticator and never leave
- Authentication assurance should match the impact of account compromise
The architecture should select an authentication assurance level from transaction and system risk, then choose authenticators and protocols that satisfy it. Identity proofing level and authentication level address different risks and need not be numerically identical.
Trap Automatically setting authentication assurance equal to identity assurance
9 questions test this
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- After tailoring, an organization decides to implement an authentication assurance level lower than the one its initial impact assessment indicated, and adds offsetting controls. NIST digital identity
- An organisation has implemented the assurance levels its impact assessment produced. NIST digital identity risk management requires an ongoing programme, fed by end-user input and performance metrics,
- A municipal utility assesses the harm from unauthorised access to its water-quality monitoring service so that it can set assurance levels. Its draft assessment counts only harm to the utility itself.
- NIST digital identity guidance separates the assurance levels that an organization selects for its online services. One of them reflects confidence that the claimant is the same individual to whom the
- Phishing resistance requires cryptographic binding to the legitimate verifier
An authenticator is phishing-resistant when its output cannot be replayed to an impostor verifier, commonly through verifier-name binding or cryptographic binding to an authenticated protected channel. Manually entered one-time passwords remain phishable even though they resist simple replay.
Trap Treating any time-limited one-time password as phishing-resistant
3 questions test this
- A hardware token displays a short numeric code that the user types into the login page, and the verifier validates it against a shared seed. A reviewer notes the design cannot be called phishing-resis
- NIST digital identity guidance recognises two ways to achieve phishing resistance: binding the authenticator output to the negotiated protected channel, and binding it to the verifier's authenticated
- An architect must document why the agency's PIV cards satisfy the phishing-resistance requirement. NIST digital identity guidance attributes it to the authentication protocol the cards use, in which t
- Risk-based elevation should occur before the higher-risk action
A session may begin at lower assurance and require step-up authentication when context or a requested operation raises risk. Elevation should produce assurance sufficient for the protected action and should not make the stronger state persist beyond its justified lifetime.
Trap Relying on post-transaction anomaly review instead of pre-action step-up
5 questions test this
- A console assessed at the highest authentication assurance level lets operators resume work after the idle limit by presenting one factor together with the existing session secret, a shortcut the guid
- In a federated deployment, the identity provider can issue a fresh assertion from a session whose authentication event happened hours earlier. NIST digital identity guidance names the authority that d
- A benefits portal lets a signed-in subscriber change the mobile number that receives its one-time codes from the profile screen, protected only by the current session. NIST digital identity guidance c
- A mobile application keeps its session secret in a protected keystore and presents it directly to the service on every request, so sessions survive a device reboot. The vendor calls the storage suffic
- A federation design assumes that when a subscriber signs out at the identity provider, the sessions at every relying party end with it. NIST digital identity guidance contradicts the assumption. Which
- Biometrics should activate an authenticator rather than stand alone remotely
NIST digital identity guidance treats a biometric characteristic as a factor used with a physical authenticator, not as an authenticator by itself. This limits replay and substitution risk while providing a local inherence check.
Trap Using a remotely submitted face image as the sole authenticator
4 questions test this
- A vendor's fingerprint system meets its false match target across the enrolled population as a whole but not for every skin tone, and proposes lowering the threshold for the affected users. NIST digit
- A bank's application unlocks its authenticator with a face image captured by the handset camera. The architect must counter an attacker who holds a printed photograph or a moulded mask in front of the
- NIST digital identity guidance declines to treat a biometric characteristic as an authenticator by itself and contrasts biometric comparison with the other authentication factors on how a match is dec
- A design retains the fingerprint images captured at each authentication so the vendor can retrain its matcher later. NIST digital identity guidance permits samples to be used for template adaptation,
- Single-factor authentication is limited to basic assurance
Single-factor authentication can satisfy AAL1 and is an architectural option only where basic confidence is adequate. When risk requires AAL2 or AAL3, the architect must select an eligible MFA process; fraud indicators or contextual checks can trigger added controls but do not raise the AAL or substitute for an authentication factor.
4 questions test this
- Single-factor authentication with a password is permitted at the basic authentication assurance level, but NIST digital identity guidance still fixes one requirement for the communication between the
- A federal agency will let subscribers view the personal information collected during identity proofing through their online account. The program office proposes a password-only sign-in because the rec
- A benefits portal adds geolocation and IP-reputation checks to its sign-in flow to lower the risk of misauthentication. Its architect has already listed these indicators in the authentication privacy
- NIST digital identity guidance permits single-factor authentication at the level that provides basic confidence in the claimant's control of a bound authenticator. It nevertheless states an expectatio
- AAL3 requires hardware-protected non-exportable authentication keys
AAL3 requires phishing-resistant public-key authentication with a non-exportable private key held in an isolated hardware environment; syncable authenticators therefore cannot satisfy AAL3. Ordinary AAL2 MFA can use exportable authenticators and need only offer, rather than universally require, a phishing-resistant option.
4 questions test this
- A department runs its staff-facing systems at the high-confidence authentication assurance level using an authenticator application for one-time passwords. Its architect notes that federal agencies ca
- An agency proposes cloud-synced passkeys for an administrative console that its risk assessment places at the highest authentication assurance level. The passkeys use public-key cryptography and are p
- A laptop authentication key is generated by a software library and encrypted at rest under the operating system user profile, and the vendor calls it non-exportable. NIST digital identity guidance wou
- An authenticator holds a symmetric secret that it shares with the verifier, and both ends store the secret in tamper-resistant hardware. NIST digital identity guidance still bars this construction at
- Authentication intent requires an explicit claimant action
Authentication intent requires the claimant to respond explicitly to each authentication or reauthentication request, such as by entering an output, pressing a button, or reinserting an authenticator. Passive biometric capture or an authenticator response that endpoint malware can trigger without the claimant's knowledge does not establish intent.
- Authenticator binding must use an authenticated protected process
Adding a new authenticator changes who can act as the subscriber, so binding requires authentication at an assurance appropriate to the account and notification of the change. An active session alone may be insufficient if it was established at lower assurance.
Trap Allowing any logged-in session to enroll an unrestricted new authenticator
5 questions test this
- Which requirement in a credential service provider's binding design gives the account owner an independent opportunity to repudiate the binding of an additional authenticator that they never initiated
- An enterprise account already has a multi-factor authenticator bound to it, but the subscriber's current browser session was established with a password alone. From that session the subscriber asks to
- Which input allows a credential service provider that accepts subscriber-owned authenticators to establish, before binding one to an account, that the offered authenticator actually has the characteri
- A bank lets subscribers enroll an authenticator that lives on a device other than the one already signed in, and the second device holds no session with the credential service provider. Which mechanis
- Which binding policy most directly reduces how often subscribers must fall back to account recovery when they lose the single device that they use to authenticate every day, without lowering the assur
- Account recovery must be engineered as an alternate authentication path
Recovery can bypass the primary authenticator, so its evidence, delay, notification, and fraud controls must match the resulting risk. Strong daily authentication is defeated by weak knowledge-based reset questions.
Trap Using easily researched personal questions to recover a high-assurance account
6 questions test this
- Attackers have repeatedly persuaded service-desk agents to rebind authenticators after correctly describing a subscriber's job title and manager. Which form of proof should the architect require from
- A financial services firm initially identity-proofed its subscriber accounts at IAL2 and requires a hardware authenticator for daily sign-in, while its self-service reset page still admits anyone who
- Which action must a credential service provider take immediately after a saved recovery code issued at enrollment has been used successfully to recover a subscriber account that has to remain recovera
- Which design element ensures that the legitimate owner of a subscriber account learns that a recovery has completed, in the case where the only other notification address held on the account is the on
- Which step must a credential service provider complete before a personal email address that a subscriber adds after enrollment, and that was not validated during identity proofing, may be used to deli
- Which binding policy most directly reduces how often subscribers must fall back to account recovery when they lose the single device that they use to authenticate every day, without lowering the assur
- Compromise response revokes the affected authenticator binding
When an authenticator is lost, stolen, or compromised, the credential service provider should promptly invalidate its binding and establish a replacement through an approved process. Changing an account label or directory password does not revoke an independent token or certificate.
Trap Renaming the account while leaving the compromised certificate valid
6 questions test this
- Which response does authentication guidance require once an incident team has confirmed that a subscriber's authenticator was duplicated by an attacker, rather than deferring the credential change to
- A contractor's smart card holding an authentication certificate is stolen. The identity team renames the directory account and resets its password, yet the credential still authenticates successfully
- An employee resigns and hands back a hardware authenticator that stores personal information. The architect is writing the offboarding standard covering both the account binding and the returned devic
- A subscriber reports that a hardware authenticator was probably left in a hotel room and may still be recovered intact. The architect wants a response that protects the account while allowing the devi
- How should a design treat the case in which a subscriber still physically holds a cryptographic authenticator, but the activation secret that unlocks it has been observed by another person and is no l
- Subscribers must be able to report a lost authenticator quickly, and the report itself has to be trustworthy enough to trigger invalidation of the binding. Which method should the architect provide fo
- Password systems should store salted, computationally resistant verifiers
Verifiers should store passwords in a form resistant to offline guessing, using salts and a suitable password hashing scheme, rather than reversible encryption or plaintext. Transport protection does not mitigate theft of a weak verifier database.
Trap Encrypting all passwords under one recoverable database key
4 questions test this
- Which property is missing from a password verifier design in which two subscribers who happen to choose the same password end up with identical stored values, so that recovering one value immediately
- Which addition to a password verifier design keeps an exported table of stored password values useless to an attacker who has never obtained the secret material held inside the organization's hardware
- A design review finds that authentication traffic is protected with TLS and the database volume is encrypted at rest, while stored password verifiers are single-pass SHA-256 values. Which risk should
- A legacy application encrypts every stored password under one database key so that support staff can read them during calls. After an export of that database leaked, the architect must replace the sto
- Online guessing defenses must rate-limit failed authentication attempts
Authentication services should throttle or otherwise limit consecutive failed attempts against an account or authenticator. Password complexity alone does not control high-volume online guessing, while permanent lockout can create a denial-of-service path.
Trap Using irreversible account lockout as the primary guessing defense
- Authenticated sessions require protected bindings and bounded lifetimes
A session inherits no higher assurance than its authentication event and maintains continuity through a protected session secret established at authentication. Overall and inactivity limits must drive reauthentication or termination, while logout or expiry invalidates the binding; successful reauthentication resets the applicable limits.
10 questions test this
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A portal hands every anonymous visitor a session identifier and keeps the same value after that visitor signs in. A tester shows that an identifier planted in a victim's browser before sign-in still n
- A web application ends sessions purely through the expiry attribute it sets on the session cookie, and keeps no server-side record of when each session began. Auditors ask how a session ends when the
- During a partial outage a service fails over to a plain HTTP status page that still receives the browser's session cookie. The vendor argues that the page displays no sensitive data and that the outag
- A subscriber signs in to a portal with a password alone, and the portal opens a session. Two hours later that same session is used to approve a high-value transfer, which policy places at a higher aut
- An analyst works inside one authenticated session from market open to close and never leaves the keyboard. The architect must ensure that a session secret stolen mid-morning cannot be ridden for the r
- Kerberos provides trusted-third-party, ticket-based authentication
Kerberos uses a key distribution center to issue a ticket-granting ticket and service tickets, allowing a client and service to authenticate without sending the user's password to each service. Its design depends on protected keys and sufficiently synchronized clocks.
Trap Selecting LDAP merely because directory entries contain user accounts
4 questions test this
- In Kerberos a client sends a cleartext request to the authentication service and receives a credential encrypted in its own secret key. The client later uses that credential to authenticate itself to
- Two manufacturers each operate their own Kerberos realm. They now want a client registered in the first organization to prove its identity to servers run by the second, without creating accounts for t
- A plant operator's hosts drift by tens of minutes because no reliable time source reaches the production network. The proposed Kerberos design still expects application servers to bound the interval o
- An engineering team asks how a workstation proves the user's identity to an internal file server hours after logon. The file server never contacts the key distribution center while it handles the requ
- RADIUS centralizes authentication and authorization for network access
A network access server can send a RADIUS Access-Request to a centralized server and receive accept, reject, challenge, and authorization attributes. RADIUS accounting is a related protocol function, but base RADIUS does not provide end-to-end protection for every attribute.
Trap Choosing Kerberos as the native AAA protocol for dial-in or network access servers
3 questions test this
- A campus wireless design terminates 802.1X sessions on access points that implement no authentication method of their own. Each access point places the messages it receives from a supplicant into RADI
- A carrier bills subscribers for connection time, so its access servers must report to a central server when each session begins and ends, along with the elapsed time and octet counts for the service t
- A subscriber's password is accepted, but the central server also requires a one-time value from the subscriber's hardware token before it will decide the request. The exchange has to continue within t
- SAML carries signed security assertions between federation parties
SAML is suited to browser-based enterprise federation in which an identity provider asserts authentication and attributes to a service provider. The assertion must be validated for issuer, signature, audience, conditions, and replay constraints rather than trusted because it is XML.
Trap Using OAuth access tokens as a direct replacement for SAML authentication assertions
4 questions test this
- A manufacturer must let employees open an external SaaS application in their browsers without the vendor ever storing or verifying employee credentials. The corporate identity provider will state who
- A service provider's implementation confirms that the response document contains one valid signature, then selects the assertion element by tag name and reads the identity from whichever element it fi
- A federation must ensure that a subscriber presenting an assertion also proves control of an authenticator bound to that assertion, so that a statement captured in transit cannot simply be presented b
- A captured browser response can be posted a second time to the assertion consumer service and is still accepted, because that service keeps no record of the assertions it has already processed and the
- OAuth delegates resource access rather than defining user authentication
OAuth lets a client obtain limited access to a protected resource on behalf of a resource owner or itself without receiving the owner's credentials. Treating a bare OAuth authorization response as proof of user identity creates an authentication design gap.
Trap Assuming possession of any OAuth access token proves the user's identity to the client
4 questions test this
- In an OAuth deployment the client must never receive the user's password. One component authenticates the resource owner directly, obtains that owner's authorization, and then issues the credential th
- A mobile client signs a user in locally on the strength of an access token it received from a partner's authorization server. The reviewing architect notes that the framework gives the client no way t
- A nightly reconciliation job must call a partner's protected API under its own identity. No employee is present to approve the access, and the job is never to hold any end user's credentials at any po
- One framework enables a third-party application to obtain limited access to an HTTP service on behalf of a resource owner, by orchestrating an approval interaction between the owner and that service i
- LDAP retrieves directory information while XACML expresses access policy
LDAP defines operations for accessing and modifying distributed directory entries; XACML defines an attribute-based policy language and request-response model for authorization decisions. Either may support an access-control architecture, but they are not interchangeable authentication protocols.
Trap Selecting LDAP as the policy language for centralized authorization decisions
5 questions test this
- Which capability is missing when a directory-only design grants entitlements from group membership alone, but policy also requires denial based on an unmanaged connecting device or access outside publ
- An architect must decide which component remains the system of record for subscriber identity data in a design that already includes an attribute-based policy service. That service evaluates rules and
- Every application in a hospital group embeds its permission checks in code, so one changed rule takes six release cycles to reach them all. The architect must leave enforcement in each application whi
- A bank runs forty applications, each carrying its own permission logic in code. The architect wants one rule set, evaluated when a request arrives, against subject, resource, action and environment at
- Two agencies must exchange authorization decisions between a claims platform and a partner's case-management product from another vendor. Each product reads identities from its own directory, and the
- OAuth grant selection follows the authorizing actor
Use an authorization-code pattern when a client needs delegated access approved by a resource owner; the authorization server mediates that approval without exposing the owner's credentials to the client. Use client credentials only for a confidential client acting on its own resources or under prearranged authority, because client authentication itself is then the grant.
- Kerberos cross-realm access inherits its KDC trust path
Cross-realm Kerberos depends on inter-realm keys and every permitted realm in the transited authentication path, so services should accept only paths allowed by policy. KDC availability is required to issue new tickets, and compromise of a realm's KDC compromises authentication for its registered principals and relying services.
3 questions test this
- A conglomerate operates forty authentication realms after a decade of acquisitions, and the architect will not create a separate direct trust for every pair of them. Clients must still authenticate to
- An application server receives a ticket from a client whose authentication reached it through a chain of realms, one of which the service owner has never assessed. Business policy allows only vetted r
- A network partition leaves a realm's authentication servers unreachable, while clients and application servers stay online and keep talking to each other. Users who authenticated before the partition
- Federation requires explicit technical and governance trust
A relying party should trust assertions only from approved identity providers under defined agreements covering assurance, attributes, keys, incident handling, and lifecycle duties. Protocol interoperability alone does not establish organizational trust.
Trap Accepting assertions from any provider that implements the same federation protocol
4 questions test this
- Two agencies operate identity systems that implement the same federation protocol profile and can already exchange technically valid, correctly signed assertions. Their architects agree that this tech
- A relying party will accept federated authentication for one business unit of a large enterprise, not for every account the identity provider is able to assert. Its architect insists that this limit b
- A consortium body admits identity providers and relying parties to a multilateral trust agreement and outsources the required onboarding checks to an external assessor. A member relying party asks who
- A multilateral federation vetted every member organization against the terms of its trust agreement when each one joined. Several members have since changed their proofing vendors and their hosting ar
- Federation assertions must be bound to their intended relying party
Audience and recipient restrictions prevent an assertion issued for one relying party from being accepted by another. Signature validation proves integrity and issuer control but does not by itself establish that the current recipient is authorized to consume it.
Trap Accepting any correctly signed assertion from a trusted issuer
- Short assertion validity and replay defenses limit federation abuse
Assertions should carry bounded validity and transaction protections appropriate to their federation assurance level. A stolen bearer assertion can be reused within its accepted scope unless nonce, audience, replay detection, or holder-of-key controls constrain it.
Trap Relying on transport encryption alone after a bearer assertion is stolen
3 questions test this
- Which of the following changes most reduces the value to an attacker of an assertion that has been captured, in a federation design where relying parties keep no record of the assertions they have alr
- An attacker intercepts a federation response and substitutes a different but perfectly valid assertion that the same identity provider issued for another subscriber. The relying party's checks find no
- Which of the following presentation methods stops a relying party from accepting an assertion that did not arrive directly from the identity provider, in a design where assertions currently travel thr
- Federation should release only attributes required by the relying party
The identity provider and relying party should agree on the minimum attributes and purposes needed for the transaction. Sending a complete enterprise profile increases privacy and breach impact without increasing authentication assurance.
Trap Replicating the full directory record to simplify relying-party integration
5 questions test this
- Which of the following identifier techniques prevents two relying parties that receive assertions for the same subscriber from the same identity provider from correlating their records into a single p
- Which of the following identifier techniques prevents two relying parties that receive assertions for the same subscriber from the same identity provider from correlating their records into a single p
- Which of the following capabilities lets a relying party read only the attributes it actually needs from a signed attribute bundle, while still verifying the issuing authority's signature over that bu
- A public-facing service uses an identity provider where each subscriber is the party authorized to release their own attributes. The provider must obtain positive confirmation naming the attributes be
- Which of the following identifier techniques prevents two relying parties that receive assertions for the same subscriber from the same identity provider from correlating their records into a single p
- Federation trades local credential control for shared identity trust
Federation reduces duplicate credentials and centralizes authentication, but creates dependency on the identity provider's availability, assurance, and incident response. A stand-alone identity store may be justified where isolation or autonomy outweighs those operational benefits.
Trap Assuming federation always reduces risk because it reduces password stores
3 questions test this
- An identity provider notifies a relying party that a subscriber account it has asserted is suspected of compromise. The relying party has already granted sessions to that account over the past week. W
- A classified programme may not let any outside party hold or assert identity attributes for its users, and it must keep authenticating those users during long periods of network isolation. Which ident
- A new service will be used by staff from several partner organizations, each of which already issues authenticators to its own people and runs its own account recovery. The department wants to issue n
- Federation assurance strengthens assertion presentation independently
FAL1 permits bearer assertions and flexible trust and key establishment, while FAL2 remains bearer-based but requires pre-established trust and strong assertion-injection protection in an RP-initiated transaction. FAL3 requires the relying party to verify subscriber control of a holder-of-key or bound authenticator in addition to validating the assertion, protecting even against a compromised identity provider.
3 questions test this
- A relying party accepts sign-in links that its identity provider initiates from a staff portal. The architect must raise this deployment to the federation assurance level that requires strong protecti
- A relying party allows routine account viewing at FAL2 and reserves payment release for FAL3. A subscriber arrives with an assertion that satisfies only the FAL2 requirements. Which response does NIST
- At the highest federation assurance level, NIST digital identity guidance withdraws the dynamic path that lower levels allow for exchanging the identifiers of the credential service provider, identity
- Federated account linking requires unique resolution and prior authentication
Before associating a new federated identifier with a local account, the relying party must use sufficient asserted attributes to resolve the subscriber uniquely and prevent association with another person's account. Linking an additional identifier should occur only in an authenticated session established through an existing identifier, not solely from a mutable attribute such as an email address.
5 questions test this
- Which mitigation does NIST digital identity guidance list so that a relying party using an attribute bundle from a subscriber-controlled wallet can detect an attribute the issuer has since withdrawn,
- Which mitigation does NIST digital identity guidance list so that a relying party using an attribute bundle from a subscriber-controlled wallet can detect an attribute the issuer has since withdrawn,
- A workforce portal lets staff attach a second identity provider to an account they already hold. The current design starts that flow from the public landing page and picks the account by the email add
- A relying party already holds member records that carry no federated identifier. It plans to attach an incoming assertion to the matching record the first time each subscriber signs in. Which conditio
- Which mitigation does NIST digital identity guidance list so that a relying party using an attribute bundle from a subscriber-controlled wallet can detect an attribute the issuer has since withdrawn,
Architect identity authorization
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Architect identity accounting
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.