Courseiva

CISSP · topic practice

Security Architecture and Engineering practice questions

Security Architecture and Engineering covers secure design principles, cryptographic selection and key management, PKI trust models, and access control enforcement. Questions present a scenario with a stated constraint and ask you to pick the control, algorithm, or model that satisfies it. Expect to reason about block versus stream ciphers, certificate validation paths, and mandatory access control rules rather than recall definitions alone.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Architecture and Engineering

What the exam tests

What to know about Security Architecture and Engineering

Map each scenario's stated constraint to the correct control: pick AES for NIST-approved block encryption, OCSP for efficient revocation checking, and the right access model for the stated integrity or confidentiality goal. The single most important thing is matching the model or algorithm to the exact requirement, not the most familiar option.

Selecting NIST-approved block ciphers such as AES for data-at-rest encryption requirements

Verifying certificate revocation efficiently using OCSP rather than a centralized CRL distribution point

Designing PKI trust chains across root CA, intermediate CAs, and end-entity certificates

Applying Bell-LaPadula no write up and no read down integrity and confidentiality rules

Watch out for

Common Security Architecture and Engineering exam traps

  • ▸Confusing Bell-LaPadula confidentiality rules with Biba integrity rules, or reversing the no read up and no write down directions
  • ▸Choosing symmetric encryption for key distribution or asymmetric encryption for bulk data, ignoring performance and key exchange roles
  • ▸Treating OCSP and CRL as interchangeable, missing that OCSP avoids full-list downloads and supports real-time status

Practice set

Security Architecture and Engineering questions

20 questions · select your answer, then reveal the explanation

An organization is implementing a PKI for internal use. To ensure that certificate revocation status is checked in real-time without relying on periodic CRL downloads, which mechanism should be used?

A company is designing a secure application that requires hardware-based key storage and remote attestation. Which THREE technologies provide hardware root of trust? Select three.

A financial institution is implementing a Clark-Wilson integrity model. Which THREE components are essential to this model?

In the context of the Clark-Wilson integrity model, which of the following are key elements? (Choose TWO)

A security architect is designing a system for a military intelligence agency where data classification labels (Top Secret, Secret, Confidential, Unclassified) are mandatory. Users are cleared to a specific level and must not read data above their clearance. Which security model enforces this type of access control?

A financial application requires strict integrity controls to prevent unauthorized modifications. The security team implements a model where users cannot write data to higher integrity levels (no write up) and cannot read data from lower integrity levels (no read down). Which model is being applied?

Question 7easymultiple choice
Study the full ACL explanation →

Which access control model allows data owners to grant or revoke access to resources they own, typically implemented using ACLs?

A security architect is selecting a cryptographic algorithm for encrypting data at rest in a backup system. The system requires strong security with a block cipher, and the organization mandates using a NIST-approved algorithm with key sizes of 128, 192, or 256 bits. Which algorithm should be selected?

A security engineer is analyzing a vulnerability where an attacker can cause a buffer overflow on the stack. Which mitigation technique randomizes memory addresses to make it harder for the attacker to predict the location of shellcode or return addresses?

Which of the following is a primary function of a Trusted Platform Module (TPM)?

Question 11mediummultiple choice
Study the full virtualization explanation →

A security architect is evaluating hypervisor security for a multi-tenant cloud environment. Which type of hypervisor is considered more secure because it runs directly on the hardware without a host operating system, reducing the attack surface?

Which physical security design principle emphasizes that the physical environment should be designed to discourage criminal activity by using natural surveillance, access control, and territorial reinforcement?

A security analyst discovers that an application allows a user to read a file they just wrote before the file's integrity is verified, due to a gap between the time of check and time of use. This is an example of which vulnerability?

A security architect is designing a system that must prevent conflicts of interest when a consultant works for two competing clients. Which security model ensures that the consultant cannot access data from one client if they have already accessed data from the other?

Which component of a trusted computing base (TCB) implements the reference monitor concept by enforcing access control decisions for all subjects and objects in the system?

A security architect is evaluating access control models for a healthcare system where users have specific roles (e.g., doctor, nurse, admin) and permissions are assigned based on those roles. However, the architect also wants to incorporate attributes such as time of day, patient consent status, and device type. Which TWO models should be combined to meet these requirements?

A security engineer is investigating a covert channel in a system. Which TWO types of covert channels could be used to leak information from a high-security to a low-security process?

An organization is implementing a defense-in-depth strategy for a data center. Which THREE of the following are examples of physical security controls that align with layered defense?

A government agency requires a security model that prevents users from reading documents at a higher classification level and from writing to documents at a lower classification level. Which model enforces these constraints?

An organization implements a security model where users can only read objects at or below their security clearance, and can only write to objects at or above their clearance. This model primarily ensures:

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Architecture and Engineering sessions

Start a Security Architecture and Engineering only practice session

Every question in these sessions is drawn from the Security Architecture and Engineering domain — nothing else.

Related practice questions

Related CISSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISSP exam test about Security Architecture and Engineering?
Map each scenario's stated constraint to the correct control: pick AES for NIST-approved block encryption, OCSP for efficient revocation checking, and the right access model for the stated integrity or confidentiality goal. The single most important thing is matching the model or algorithm to the exact requirement, not the most familiar option.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Architecture and Engineering questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Architecture and Engineering domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISSP topics?
Use the topic links above to move to related areas, or go back to the CISSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISSP exam covers. They are not copied from any real exam or dump site.