Sample questions
(ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) practice questions
When designing a secure multi-region cloud architecture, which THREE governance aspects must be clearly defined for data residency compliance?
What is the primary objective of a 'Compliance Gap Analysis' in a cloud migration project?
Which THREE criteria are most important when selecting a Cloud Service Provider (CSP) based on the Shared Responsibility Model for an ISSAP architect?
You are deploying OIDC (OpenID Connect) for a web application. You need to prevent token replay attacks. Which claim should the application validate in the ID Token?
Identity And Access Management ArchitecturehardSee the answer and why each option is right or wrong →Which TWO methods are used to prevent 'Token Replay' attacks in an OAuth/OIDC architecture?
Identity And Access Management ArchitecturehardSee the answer and why each option is right or wrong →A security architect is hardening a Linux-based server environment. Which TWO of the following kernel-level security modules should be configured to enforce mandatory access contro…
An ISSAP architect is designing a cloud environment that must comply with PCI-DSS 4.0. Which specific AWS feature should be configured within the AWS Control Tower to ensure that a…
To implement effective Risk Management integration into architecture using the FAIR (Factor Analysis of Information Risk) framework, which THREE metrics must an architect define fo…
An ISSAP architect is working with developers to ensure that the code repository is compliant with secure coding standards. Which tool within the GitHub ecosystem is specifically d…
When establishing a Third-Party Risk Management (TPRM) process, which THREE factors must be considered during the initial due diligence?
When implementing FIDO2/WebAuthn for passwordless authentication, where does the private key reside?
Identity And Access Management ArchitecturemediumSee the answer and why each option is right or wrong →When using an API Gateway as a Policy Enforcement Point (PEP), where should the authorization decision logic be offloaded to ensure central governance?
Identity And Access Management ArchitecturehardSee the answer and why each option is right or wrong →Which governance model is characterized by decision-making being centralized at the corporate level to ensure consistency across the entire organization?
A firm needs to ensure that only approved machine images (AMIs) are used in production. Which AWS service should be used to create a golden image pipeline that enforces compliance…
In a Zero Trust architecture, what is the primary role of a Policy Decision Point (PDP)?
Identity And Access Management ArchitecturemediumSee the answer and why each option is right or wrong →An organization is building a microservices architecture. To ensure compliance with GDPR, where should the data classification metadata be enforced to ensure that PII is not stored…
You are designing an Azure AD (Entra ID) Conditional Access policy to restrict access to sensitive applications. You need to ensure that only compliant, managed devices can access…
Identity And Access Management ArchitecturemediumSee the answer and why each option is right or wrong →To implement governance for containerized workloads, which Kubernetes feature should an architect use to enforce that only images from a trusted registry are deployed?
In the context of the CISSP-ISSAP, which governance activity involves verifying that the architecture aligns with business requirements through regular audits?
An architect is evaluating compliance for an enterprise multi-cloud environment. Which THREE capabilities must be included in a centralized GRC platform for it to be effective?
Which risk management framework is most commonly used for aligning business objectives with IT capabilities in large enterprises?
When designing an architecture to meet NIST 800-53 controls, which AWS service should be used to enforce resource tagging for all assets to ensure proper cost and compliance tracki…
Which TWO factors are critical when establishing a Risk Appetite statement for a new cloud-native architecture?
Which authentication factor is considered 'inherence'?
Identity And Access Management ArchitectureeasySee the answer and why each option is right or wrong →