Practice ISC Security Architecture Modeling questions with full explanations on every answer.
Start practicing
Security Architecture Modeling — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are designing a reference architecture for a cloud environment. Which NIST document provides the most relevant framework for cloud security architecture?
2In a SABSA (Sherwood Applied Business Security Architecture) model, you are mapping business attributes to security services. Which layer focuses on the 'What' from a business perspective?
3In the context of Enterprise Security Architecture, what is the primary goal of the 'Capability Maturity Model' (CMM) integration?
4You are implementing threat modeling using the PASTA (Process for Attack Simulation and Threat Analysis) framework. What is the primary output of Stage 2?
5When conducting threat modeling using the STRIDE methodology, which category addresses a user gaining unauthorized access to an administrative account?
6You are utilizing TOGAF 10 to develop an Architecture Content Framework. Which component of the Architecture Development Method (ADM) phase A is specifically required to define the scope and identify stakeholders?
7In the context of TOGAF, what is the 'Architecture Repository' used for?
8Which document is the primary deliverable of the TOGAF 'Architecture Definition Document'?
9What is the primary function of a Security Reference Architecture (SRA)?
10When performing an architectural review of a CI/CD pipeline, which security control is most critical for preventing unauthorized deployment of code?
11Which tool would you use to visualize the data flow between components in a cloud-native application for threat modeling?
12When evaluating a software-defined perimeter (SDP), which architecture principle is being primarily enforced?
13Which threat modeling technique is best described as focusing on the attacker's perspective and their motivation?
14When designing a secure API architecture, which pattern is the industry standard for securing inter-service communication?
15Which type of diagram is used to represent the different zones in an architecture?
16In the context of the SABSA framework, what is the relationship between the 'Security Services' and 'Business Attributes'?
17Which threat modeling tool is known for generating DFDs and identifying threats via a rule engine?
18When designing an architecture, which principle states that a system should be designed to be secure even if other security measures fail?
19What is the primary purpose of an 'Architecture Trade-off Analysis Method' (ATAM)?
20When using the 'Trike' methodology for threat modeling, which of the following is the main focus?
21In the context of the CISSP-ISSAP, which architecture framework is most commonly used for federal government IT systems?
22When designing for 'Availability' in a distributed architecture, which pattern is used to handle service failure gracefully?
23Which component of an architecture document defines the communication standards between services?
24Which component is the most critical to protect in a web-based architecture?
25Which security principle is enforced when you restrict an application's ability to modify system files?
26When documenting a cloud-based architecture, which aspect is most critical to document for compliance?
27In the context of the 'Zachman Framework', which cell represents the 'Why' of the security architecture?
28What is the primary function of a Security Content Automation Protocol (SCAP) in architecture?
29Which THREE components are typically included in an Enterprise Security Architecture (ESA) framework? (Select THREE)
30When evaluating architectural threats, which THREE categories are explicitly defined in the STRIDE methodology? (Select THREE)
31Which THREE items should be included in a thorough Architecture Decision Record (ADR)? (Select THREE)
32Which TWO of the following are primary goals of conducting threat modeling during the architecture phase? (Select TWO)
33Which TWO are common challenges in Enterprise Security Architecture? (Select TWO)
34In the TOGAF ADM, which TWO phases are most critical for security architecture integration? (Select TWO)
35Which THREE elements are essential to define a trust boundary? (Select THREE)
36Which THREE principles are core to a 'Zero Trust' architecture? (Select THREE)
37Which TWO elements are required to effectively document a security architecture for audit purposes? (Select TWO)
38When modeling threats for a microservices architecture, which TWO threats are most relevant due to service distribution? (Select TWO)
39Which TWO types of documentation are standard in the SABSA methodology? (Select TWO)
40Which THREE of the following are considered 'Assets' in security architecture? (Select THREE)
41Which THREE factors influence the choice of a security architecture framework? (Select THREE)
42When designing a secure cloud architecture, which TWO security services are essential for identity and access management? (Select TWO)
The Security Architecture Modeling domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 42 questions in the Security Architecture Modeling domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Architecture Modeling domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included