Courseiva

ISC · topic practice

Security Architecture Modeling practice questions

Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) Security Architecture Modeling practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security Architecture Modeling

What the exam tests

What to know about Security Architecture Modeling

Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Architecture Modeling exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Security Architecture Modeling questions

20 questions · select your answer, then reveal the explanation

Which architecture pattern is specifically designed to isolate sensitive processes from the rest of the network?

When documenting security architecture, which component of the ISO/IEC 27001 standard is most closely aligned with the 'Statement of Applicability'?

You are designing a reference architecture for a cloud environment. Which NIST document provides the most relevant framework for cloud security architecture?

In a SABSA (Sherwood Applied Business Security Architecture) model, you are mapping business attributes to security services. Which layer focuses on the 'What' from a business perspective?

In the context of Enterprise Security Architecture, what is the primary goal of the 'Capability Maturity Model' (CMM) integration?

You are implementing threat modeling using the PASTA (Process for Attack Simulation and Threat Analysis) framework. What is the primary output of Stage 2?

When conducting threat modeling using the STRIDE methodology, which category addresses a user gaining unauthorized access to an administrative account?

You are utilizing TOGAF 10 to develop an Architecture Content Framework. Which component of the Architecture Development Method (ADM) phase A is specifically required to define the scope and identify stakeholders?

In the context of TOGAF, what is the 'Architecture Repository' used for?

Which document is the primary deliverable of the TOGAF 'Architecture Definition Document'?

What is the primary function of a Security Reference Architecture (SRA)?

When performing an architectural review of a CI/CD pipeline, which security control is most critical for preventing unauthorized deployment of code?

Which tool would you use to visualize the data flow between components in a cloud-native application for threat modeling?

When evaluating a software-defined perimeter (SDP), which architecture principle is being primarily enforced?

Which threat modeling technique is best described as focusing on the attacker's perspective and their motivation?

When designing a secure API architecture, which pattern is the industry standard for securing inter-service communication?

Which type of diagram is used to represent the different zones in an architecture?

In the context of the SABSA framework, what is the relationship between the 'Security Services' and 'Business Attributes'?

Which threat modeling tool is known for generating DFDs and identifying threats via a rule engine?

When designing an architecture, which principle states that a system should be designed to be secure even if other security measures fail?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Architecture Modeling sessions

Start a Security Architecture Modeling only practice session

Every question in these sessions is drawn from the Security Architecture Modeling domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Security Architecture Modeling?
Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Architecture Modeling questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Architecture Modeling domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.