Courseiva

ISC · domain

Security Architecture Modeling

Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) Security Architecture Modeling practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

42 questions12 easy15 medium15 hard

Focused practice

Practice Security Architecture Modeling questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Architecture Modeling

Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Architecture Modeling exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Architecture Modeling questions (42)

Click any question to see the full explanation, or start a practice session above.

1

When designing an architecture, which principle states that a system should be designed to be secure even if other security measures fail?

Easy
2

When documenting a cloud-based architecture, which aspect is most critical to document for compliance?

Hard
3

You are implementing threat modeling using the PASTA (Process for Attack Simulation and Threat Analysis) framework. What is the primary output of Stage 2?

Hard
4

In a SABSA (Sherwood Applied Business Security Architecture) model, you are mapping business attributes to security services. Which layer focuses on the 'What' from a business perspective?

Hard
5

Which THREE principles are core to a 'Zero Trust' architecture? (Select THREE)

Medium
6

When designing a secure API architecture, which pattern is the industry standard for securing inter-service communication?

Hard
7

When conducting threat modeling using the STRIDE methodology, which category addresses a user gaining unauthorized access to an administrative account?

Easy
8

What is the primary function of a Security Reference Architecture (SRA)?

Easy
9

What is the primary function of a Security Content Automation Protocol (SCAP) in architecture?

Medium
10

In the context of Enterprise Security Architecture, what is the primary goal of the 'Capability Maturity Model' (CMM) integration?

Hard
11

Which tool would you use to visualize the data flow between components in a cloud-native application for threat modeling?

Easy
12

Which TWO elements are required to effectively document a security architecture for audit purposes? (Select TWO)

Easy
13

Which document is the primary deliverable of the TOGAF 'Architecture Definition Document'?

Medium
14

When designing a secure cloud architecture, which TWO security services are essential for identity and access management? (Select TWO)

Hard
15

When using the 'Trike' methodology for threat modeling, which of the following is the main focus?

Medium
16

In the context of the CISSP-ISSAP, which architecture framework is most commonly used for federal government IT systems?

Medium
17

Which THREE components are typically included in an Enterprise Security Architecture (ESA) framework? (Select THREE)

Medium
18

Which THREE of the following are considered 'Assets' in security architecture? (Select THREE)

Easy
19

Which type of diagram is used to represent the different zones in an architecture?

Easy
20

Which THREE elements are essential to define a trust boundary? (Select THREE)

Medium
21

Which THREE items should be included in a thorough Architecture Decision Record (ADR)? (Select THREE)

Medium
22

You are designing a reference architecture for a cloud environment. Which NIST document provides the most relevant framework for cloud security architecture?

Medium
23

Which security principle is enforced when you restrict an application's ability to modify system files?

Easy
24

In the context of the SABSA framework, what is the relationship between the 'Security Services' and 'Business Attributes'?

Hard
25

When designing for 'Availability' in a distributed architecture, which pattern is used to handle service failure gracefully?

Hard
26

Which threat modeling technique is best described as focusing on the attacker's perspective and their motivation?

Easy
27

Which TWO are common challenges in Enterprise Security Architecture? (Select TWO)

Easy
28

What is the primary purpose of an 'Architecture Trade-off Analysis Method' (ATAM)?

Hard
29

Which TWO types of documentation are standard in the SABSA methodology? (Select TWO)

Hard
30

When evaluating a software-defined perimeter (SDP), which architecture principle is being primarily enforced?

Medium
31

Which component is the most critical to protect in a web-based architecture?

Easy
32

When evaluating architectural threats, which THREE categories are explicitly defined in the STRIDE methodology? (Select THREE)

Hard
33

In the context of TOGAF, what is the 'Architecture Repository' used for?

Medium
34

In the TOGAF ADM, which TWO phases are most critical for security architecture integration? (Select TWO)

Hard
35

In the context of the 'Zachman Framework', which cell represents the 'Why' of the security architecture?

Hard
36

Which THREE factors influence the choice of a security architecture framework? (Select THREE)

Medium
37

When modeling threats for a microservices architecture, which TWO threats are most relevant due to service distribution? (Select TWO)

Hard
38

Which component of an architecture document defines the communication standards between services?

Medium
39

You are utilizing TOGAF 10 to develop an Architecture Content Framework. Which component of the Architecture Development Method (ADM) phase A is specifically required to define the scope and identify stakeholders?

Medium
40

When performing an architectural review of a CI/CD pipeline, which security control is most critical for preventing unauthorized deployment of code?

Hard
41

Which TWO of the following are primary goals of conducting threat modeling during the architecture phase? (Select TWO)

Easy
42

Which threat modeling tool is known for generating DFDs and identifying threats via a rule engine?

Medium

Frequently asked questions

What does the Security Architecture Modeling domain cover on the ISC exam?
Security Architecture Modeling questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 42 Security Architecture Modeling questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Architecture Modeling questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-issap ISC2-ISSAP security architecture modeling Practice Questions