Courseiva
Back to (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) questions

Scenario-based practice

Hard Difficulty Questions

Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
ISC
exam code
(ISC)²
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related ISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A firm is using Terraform for Infrastructure as Code (IaC) governance. The architect wants to prevent the deployment of insecure security groups. Which tool should be integrated into the CI/CD pipeline to perform static analysis against defined security policies?

Question 2hardmulti select
Full question →

When designing a secure multi-region cloud architecture, which THREE governance aspects must be clearly defined for data residency compliance?

Question 3hardmultiple choice
Full question →

You are deploying OIDC (OpenID Connect) for a web application. You need to prevent token replay attacks. Which claim should the application validate in the ID Token?

Question 4hardmulti select
Full question →

Which TWO methods are used to prevent 'Token Replay' attacks in an OAuth/OIDC architecture?

Question 5hardmulti select
Full question →

A security architect is hardening a Linux-based server environment. Which TWO of the following kernel-level security modules should be configured to enforce mandatory access control?

Question 6hardmulti select
Full question →

To implement effective Risk Management integration into architecture using the FAIR (Factor Analysis of Information Risk) framework, which THREE metrics must an architect define for each identified scenario?

Question 7hardmultiple choice
Full question →

When using an API Gateway as a Policy Enforcement Point (PEP), where should the authorization decision logic be offloaded to ensure central governance?

Question 8hardmultiple choice
Full question →

A firm needs to ensure that only approved machine images (AMIs) are used in production. Which AWS service should be used to create a golden image pipeline that enforces compliance before images are shared?

Question 9hardmultiple choice
Full question →

An organization is building a microservices architecture. To ensure compliance with GDPR, where should the data classification metadata be enforced to ensure that PII is not stored in non-compliant regions?

Question 10hardmulti select
Full question →

An architect is evaluating compliance for an enterprise multi-cloud environment. Which THREE capabilities must be included in a centralized GRC platform for it to be effective?

Question 11hardmulti select
Full question →

Which TWO risks are significantly mitigated by implementing a Privileged Access Management (PAM) vault?

Question 12hardmultiple choice
Full question →

What is the primary architectural purpose of a 'Security Token Service' (STS) in a federated environment?

Question 13hardmulti select
Full question →

Which THREE of the following are risks associated with using shared cloud storage buckets?

Question 14hardmultiple choice
Full question →

You are securing a microservices architecture using mTLS. Which party is responsible for issuing the certificates that identify each service?

Question 15hardmultiple choice
Full question →

You are designing a secure data enclave using Confidential Computing. Which technology allows you to verify that the code running inside the TEE (Trusted Execution Environment) has not been tampered with?

Question 16hardmultiple choice
Full question →

You are architecting a cloud-based application that needs to share secrets between two different cloud environments (AWS and Azure). What is the most secure way to exchange credentials?

Question 17hardmultiple choice
Full question →

An organization requires that all cloud storage assets are encrypted using customer-managed keys. Which service should the architect configure to track the key usage and verify compliance?

Question 18hardmultiple choice
Full question →

A security architect is designing an authentication flow for a distributed system. Which method provides the best defense against replay attacks?

Question 19hardmultiple choice
Full question →

You are architecting a solution to mitigate 'Token Theft' in a Zero Trust environment. Which mechanism binds a token to a specific client instance?

Question 20hardmultiple choice
Full question →

When deploying HashiCorp Vault for secrets management, you need to implement a 'Dynamic Secrets' architecture for database access. Which workflow is correct?

These ISC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style ISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.