CISSP · domain
Security Architecture and Engineering
Security Architecture and Engineering covers secure design principles, cryptographic selection and key management, PKI trust models, and access control enforcement. Questions present a scenario with a stated constraint and ask you to pick the control, algorithm, or model that satisfies it. Expect to reason about block versus stream ciphers, certificate validation paths, and mandatory access control rules rather than recall definitions alone.
Focused practice
Practice Security Architecture and Engineering questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Architecture and Engineering
Map each scenario's stated constraint to the correct control: pick AES for NIST-approved block encryption, OCSP for efficient revocation checking, and the right access model for the stated integrity or confidentiality goal. The single most important thing is matching the model or algorithm to the exact requirement, not the most familiar option.
Selecting NIST-approved block ciphers such as AES for data-at-rest encryption requirements
Verifying certificate revocation efficiently using OCSP rather than a centralized CRL distribution point
Designing PKI trust chains across root CA, intermediate CAs, and end-entity certificates
Applying Bell-LaPadula no write up and no read down integrity and confidentiality rules
Watch out for
Common Security Architecture and Engineering exam traps
- ▸Confusing Bell-LaPadula confidentiality rules with Biba integrity rules, or reversing the no read up and no write down directions
- ▸Choosing symmetric encryption for key distribution or asymmetric encryption for bulk data, ignoring performance and key exchange roles
- ▸Treating OCSP and CRL as interchangeable, missing that OCSP avoids full-list downloads and supports real-time status
Question index
All Security Architecture and Engineering questions (59)
Click any question to see the full explanation, or start a practice session above.
A security architect is deploying a public key infrastructure (PKI) and wants to ensure that certificate revocation status is verified efficiently without relying on a centralized CRL distribution point. Which technique should be used?
Medium2A company is implementing an access control system where permissions are granted based on attributes such as user role, department, time of day, and device trust score. This approach allows for fine-grained policies that can adapt to context. Which access control model is being used?
Easy3A security architect is evaluating access control models for a healthcare system where users have specific roles (e.g., doctor, nurse, admin) and permissions are assigned based on those roles. However, the architect also wants to incorporate attributes such as time of day, patient consent status, and device type. Which TWO models should be combined to meet these requirements?
Medium4A security engineer is hardening a web application against race condition vulnerabilities. Which TWO techniques are effective mitigations?
Medium5A security analyst is investigating a potential covert timing channel in a system. Which of the following characteristics best describes this type of channel?
Medium6A security analyst is investigating a potential data leak via covert channels. Which of the following is an example of a timing covert channel?
Medium7An organization is evaluating a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in a file access routine. The routine checks if a user has permission to open a file, then later opens the file. Which of the following best describes the potential exploitation?
Medium8A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?
Medium9A security architect is designing a physical security perimeter for a data center. Which of the following is an example of Crime Prevention Through Environmental Design (CPTED) principle?
Easy10Which access control model allows the data owner to determine who can access their resources, typically using Access Control Lists (ACLs)?
Easy11Which component of a trusted computing base (TCB) implements the reference monitor concept by enforcing access control decisions for all subjects and objects in the system?
Easy12A government agency requires a security model that prevents users from reading documents at a higher classification level and from writing to documents at a lower classification level. Which model enforces these constraints?
Medium13A security architect is designing a system for a government agency that requires strict confidentiality controls. Data must be classified at multiple levels (e.g., Top Secret, Secret, Confidential). Users at a lower classification should not be able to read data at a higher classification, and users at a higher classification should not be able to write data to a lower classification. Which security model enforces these rules?
Medium14An organization requires a commercial integrity model where users cannot modify data in higher integrity levels and cannot read data from lower integrity levels. Which model should they implement?
Medium15Which physical security design principle emphasizes that the physical environment should be designed to discourage criminal activity by using natural surveillance, access control, and territorial reinforcement?
Medium16A security architect is designing a system that must ensure integrity of commercial transactions. Which of the following models are specifically focused on integrity? (Choose TWO)
Medium17An organization is implementing a Public Key Infrastructure (PKI) to support secure email and web communications. The PKI includes a root CA, intermediate CAs, and end-entity certificates. Which of the following best describes the role of the root CA in this hierarchy?
Medium18A financial institution must ensure that transactions are well-formed and enforce separation of duties to prevent fraud. Which security model best addresses these requirements?
Hard19Which access control model allows the owner of a resource to grant or deny access to other users?
Easy20A security architect is designing a trusted recovery capability for a high-assurance system that must continue operating during a failure without violating its security policy. The system must be able to recover from a failure while maintaining the security of the data it processes, and must not enter an insecure state during recovery. Which two recovery strategies best satisfy the requirement to maintain security during failure and recovery? (Choose two.)
Hard21A security architect is implementing a system that must prevent conflicts of interest for a consulting firm serving competing clients. Which security model is best suited for this requirement?
Medium22Which physical security concept uses natural surveillance, territorial reinforcement, and access control to deter crime in built environments?
Easy23A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?
Hard24A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?
Medium25Which cryptographic algorithm is an example of a symmetric stream cipher?
Easy26Which of the following is a primary function of a Trusted Platform Module (TPM)?
Easy27A company wants to ensure that only authorized software can run on its laptops. They decide to use a hardware component that validates the boot process by measuring each component before it loads. Which technology is being used?
Medium28An organization uses a system where access decisions are based on user attributes (e.g., job title, clearance), resource attributes (e.g., classification), and environmental factors (e.g., time of day). This is an example of:
Medium29A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?
Hard30An organization implements a security model where users can only read objects at or below their security clearance, and can only write to objects at or above their clearance. This model primarily ensures:
Medium31A security team is investigating a vulnerability where an attacker can intercept and modify data as it moves between processes within a CPU's secure enclave. Which technology is designed to protect against such attacks by creating a trusted execution environment?
Hard32Which of the following are characteristics of a Trusted Execution Environment (TEE)? (Choose TWO)
Easy33A security engineer is hardening a system against buffer overflow attacks. Which of the following are effective mitigations? (Choose THREE)
Hard34A cloud service provider uses a Type 1 hypervisor to host multiple virtual machines (VMs) for different customers. Which of the following is a primary security concern specific to this architecture?
Hard35A company is implementing a PKI to support secure web browsing. Which of the following are commonly used to enhance the security of certificate validation? (Choose TWO)
Medium36A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?
Medium37A security architect is designing a system that must enforce the principle of least privilege for a set of applications. The applications need to access a shared database, but each application should only have the minimum permissions necessary to perform its function. The architect decides to implement a mechanism where each application runs with its own set of credentials and permissions, and these permissions are checked at every access attempt. Which security principle is best demonstrated by this design?
Medium38Which cryptographic algorithm is a symmetric block cipher widely used for encrypting sensitive data, with key sizes of 128, 192, or 256 bits?
Easy39An organization deploys a hypervisor to host multiple virtual machines. To mitigate the risk of VM escape attacks, which of the following is the most effective security measure?
Hard40A security analyst is evaluating access control models for a healthcare organization that needs to enforce both confidentiality and integrity. Which TWO models should be considered? Select two.
Medium41A software vulnerability allows an attacker to overwrite a return address on the stack to execute arbitrary code. What mitigation technique randomizes the memory layout to prevent the attacker from predicting target addresses?
Hard42A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?
Medium43An organization wants to implement a security mechanism that ensures all accesses are mediated and cannot be bypassed, is tamperproof, and is small enough to be verified. This describes which concept?
Medium44During a security audit, a vulnerability scanner reports a buffer overflow vulnerability in a legacy application. The application runs on a system with Data Execution Prevention (DEP/NX) enabled and Address Space Layout Randomization (ASLR) active. Which of the following is the most likely impact of these mitigations on a typical stack-based buffer overflow exploit?
Hard45A security engineer is evaluating a system that uses a Trusted Platform Module (TPM) for secure boot. The TPM measures the boot components and stores the measurements in Platform Configuration Registers (PCRs). Which of the following is a primary security goal achieved by this process?
Hard46A security engineer is evaluating a system that uses a cryptographic module validated under FIPS 140-2. The module provides encryption and key management services. The engineer notes that the module's cryptographic boundary is defined, and it includes a hardware component that stores keys. The engineer must ensure that the module's keys are protected against unauthorized disclosure even if the host operating system is compromised. Which aspect of the module's design is most critical to achieving this protection?
Hard47A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?
Hard48A company is deploying a hypervisor to run multiple virtual servers. To minimize the risk of VM escape attacks, which type of hypervisor should they choose and what hardening measure is most effective?
Hard49A government agency requires a security model that prevents users from reading documents classified above their clearance level and from writing classified information to lower-level systems. Which model enforces these constraints?
Medium50Which type of covert channel uses the timing of events or operations to transmit information?
Easy51A security engineer is hardening a system against side-channel attacks that exploit variations in execution time or power consumption. Which TWO mitigations are specifically designed to counter such attacks? Select two.
Medium52In a PKI hierarchy, a relying party needs to verify a certificate's validity. To reduce latency and improve privacy, which mechanism allows the relying party to obtain the revocation status without contacting the CA directly for each verification?
Hard53A security architect is designing a physical security system for a data center. Which of the following is an example of a layered physical control at the perimeter?
Easy54A security architect is evaluating physical security controls for a facility handling sensitive data. Which of the following are examples of layered physical security controls? (Choose THREE)
Medium55Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?
Easy56A software developer is concerned about buffer overflow vulnerabilities. Which combination of mitigations makes it most difficult for an attacker to exploit a stack-based buffer overflow?
Medium57A security architect is evaluating hypervisor security for a multi-tenant cloud environment. Which type of hypervisor is considered more secure because it runs directly on the hardware without a host operating system, reducing the attack surface?
Medium58A security architect is designing a system to protect against side-channel attacks that exploit electromagnetic emanations. Which TWO controls are most effective?
Medium59An organization is implementing a defense-in-depth strategy for a data center. Which THREE of the following are examples of physical security controls that align with layered defense?
MediumOther domains
All CISSP exam domains
Frequently asked questions
- What does the Security Architecture and Engineering domain cover on the CISSP exam?
- Map each scenario's stated constraint to the correct control: pick AES for NIST-approved block encryption, OCSP for efficient revocation checking, and the right access model for the stated integrity or confidentiality goal. The single most important thing is matching the model or algorithm to the exact requirement, not the most familiar option.
- How many questions are in this domain?
- This page lists all 59 Security Architecture and Engineering questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Architecture and Engineering questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.