ISC · domain
Security Architecture Modeling
Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) Security Architecture Modeling practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Architecture Modeling questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Architecture Modeling
Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Architecture Modeling exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Architecture Modeling questions (42)
Click any question to see the full explanation, or start a practice session above.
When designing an architecture, which principle states that a system should be designed to be secure even if other security measures fail?
Easy2When documenting a cloud-based architecture, which aspect is most critical to document for compliance?
Hard3You are implementing threat modeling using the PASTA (Process for Attack Simulation and Threat Analysis) framework. What is the primary output of Stage 2?
Hard4In a SABSA (Sherwood Applied Business Security Architecture) model, you are mapping business attributes to security services. Which layer focuses on the 'What' from a business perspective?
Hard5Which THREE principles are core to a 'Zero Trust' architecture? (Select THREE)
Medium6When designing a secure API architecture, which pattern is the industry standard for securing inter-service communication?
Hard7When conducting threat modeling using the STRIDE methodology, which category addresses a user gaining unauthorized access to an administrative account?
Easy8What is the primary function of a Security Reference Architecture (SRA)?
Easy9What is the primary function of a Security Content Automation Protocol (SCAP) in architecture?
Medium10In the context of Enterprise Security Architecture, what is the primary goal of the 'Capability Maturity Model' (CMM) integration?
Hard11Which tool would you use to visualize the data flow between components in a cloud-native application for threat modeling?
Easy12Which TWO elements are required to effectively document a security architecture for audit purposes? (Select TWO)
Easy13Which document is the primary deliverable of the TOGAF 'Architecture Definition Document'?
Medium14When designing a secure cloud architecture, which TWO security services are essential for identity and access management? (Select TWO)
Hard15When using the 'Trike' methodology for threat modeling, which of the following is the main focus?
Medium16In the context of the CISSP-ISSAP, which architecture framework is most commonly used for federal government IT systems?
Medium17Which THREE components are typically included in an Enterprise Security Architecture (ESA) framework? (Select THREE)
Medium18Which THREE of the following are considered 'Assets' in security architecture? (Select THREE)
Easy19Which type of diagram is used to represent the different zones in an architecture?
Easy20Which THREE elements are essential to define a trust boundary? (Select THREE)
Medium21Which THREE items should be included in a thorough Architecture Decision Record (ADR)? (Select THREE)
Medium22You are designing a reference architecture for a cloud environment. Which NIST document provides the most relevant framework for cloud security architecture?
Medium23Which security principle is enforced when you restrict an application's ability to modify system files?
Easy24In the context of the SABSA framework, what is the relationship between the 'Security Services' and 'Business Attributes'?
Hard25When designing for 'Availability' in a distributed architecture, which pattern is used to handle service failure gracefully?
Hard26Which threat modeling technique is best described as focusing on the attacker's perspective and their motivation?
Easy27Which TWO are common challenges in Enterprise Security Architecture? (Select TWO)
Easy28What is the primary purpose of an 'Architecture Trade-off Analysis Method' (ATAM)?
Hard29Which TWO types of documentation are standard in the SABSA methodology? (Select TWO)
Hard30When evaluating a software-defined perimeter (SDP), which architecture principle is being primarily enforced?
Medium31Which component is the most critical to protect in a web-based architecture?
Easy32When evaluating architectural threats, which THREE categories are explicitly defined in the STRIDE methodology? (Select THREE)
Hard33In the context of TOGAF, what is the 'Architecture Repository' used for?
Medium34In the TOGAF ADM, which TWO phases are most critical for security architecture integration? (Select TWO)
Hard35In the context of the 'Zachman Framework', which cell represents the 'Why' of the security architecture?
Hard36Which THREE factors influence the choice of a security architecture framework? (Select THREE)
Medium37When modeling threats for a microservices architecture, which TWO threats are most relevant due to service distribution? (Select TWO)
Hard38Which component of an architecture document defines the communication standards between services?
Medium39You are utilizing TOGAF 10 to develop an Architecture Content Framework. Which component of the Architecture Development Method (ADM) phase A is specifically required to define the scope and identify stakeholders?
Medium40When performing an architectural review of a CI/CD pipeline, which security control is most critical for preventing unauthorized deployment of code?
Hard41Which TWO of the following are primary goals of conducting threat modeling during the architecture phase? (Select TWO)
Easy42Which threat modeling tool is known for generating DFDs and identifying threats via a rule engine?
MediumOther domains
All ISC exam domains
Frequently asked questions
- What does the Security Architecture Modeling domain cover on the ISC exam?
- Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 42 Security Architecture Modeling questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Architecture Modeling questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.