ISC2 CISSP-ISSAP Certification Sample Questions

CISSP-ISSAP Dumps, CISSP-ISSAP Dumps, CISSP-ISSAP PDF, CISSP-ISSAP VCE, ISC2 CISSP-ISSAP VCE, ISC2 ISSAP PDFThe purpose of this Sample Question Set is to provide you with information about the ISC2 Information Systems Security Architecture Professional exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CISSP-ISSAP certification test. To get familiar with real exam environment, we suggest you try our Sample ISC2 CISSP-ISSAP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISC2 Information Systems Security Architecture Professional (CISSP-ISSAP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISC2 CISSP-ISSAP exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium ISC2 CISSP-ISSAP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISC2 CISSP-ISSAP Sample Questions:

01. An architecture must bring a fleet of commercially available Internet of Things (IoT) devices into a production environment. Which assumption should the design make about the security capability of the devices themselves?
a) The devices hold nothing of value to an attacker, so controls on them add cost without reducing risk.
b) Securing them is not achievable at all, so the only defensible design keeps the fleet off any production network.
c) Capability varies by model and is often shipped disabled, so each one has to be verified and compensated for.
d) Each device arrives with its protective features enabled, so the vendor's shipped defaults can be relied on.
 
02. Open Authorization (OAuth) is an open standard for delegated authorization, published in two versions that differ in how a client demonstrates its right to call an interface. Which statement about the two versions is accurate?
a) Version 2.0 issues bearer tokens that represent a delegated user authorization.
b) Version 1.0 remains available and is recommended for new integrations.
c) Version 2.0 protects each request by signing it with a client secret rather than relying on the transport.
d) Version 1.0 issues tokens that authenticate the user to the resource server.
 
03. A privileged access management (PAM) design scopes which account types require credential vaulting, brokered and recorded sessions, and just in time elevation. Scope is set by whether the account holds a standing capability to change system configuration or data.
Which of these roles falls outside that scope?
a) Database administrators
b) System administrators
c) Mainframe operators
d) Auditors
 
04. Which activity belongs in the preparation phase of an incident response plan (IRP)?
a) Recording lessons learned and correcting the runbooks the response exposed as wrong
b) Imaging the affected hosts and preserving volatile memory for later analysis
c) Establishing the notification path and training the responders named in it
d) Isolating the affected segment and revoking the credentials known to be compromised
 
05. An incident response plan has to designate how affected stakeholders are notified. The obligation runs to identified parties within a fixed period, the organization has to be able to show that each of them was reached, and the disclosure is not to extend beyond the affected population.
Which channel should the plan designate for that notification?
a) A statement issued to the press, carried at the discretion of the outlets that receive it, and at the time they choose
b) Direct communication addressed to each affected party, with a record of what was sent and when
c) A notice on the corporate website, available to anyone who visits the page
d) A post to the organization's social media accounts, published to whoever follows them
 
06. Two organizations that run comparable platforms sign a reciprocal processing agreement as part of their recovery strategy. What does that agreement provide?
a) Each party contracts a commercial recovery provider to supply a fully equipped alternate facility on demand
b) Each party agrees to host the other's critical processing on its own capacity during a declared disruption
c) Each party stores backup media at a hardened off-site vault operated by a third party
d) Each party transfers the financial consequence of an outage to an insurer under an agreed policy limit
 
07. Before a security operations capability is designed, the architecture team gathers requirements from the business, from regulators and from the organization's contractual commitments. What is the primary purpose of gathering those requirements?
a) To set the staffing roster for the monitoring shifts
b) To select the vendors that will supply monitoring services
c) To fix the tooling budget and headcount before design begins
d) To ensure operations satisfy legal and compliance obligations
 
08. Why does an application architecture depend on secure application programming interfaces (APIs) for service-to-service communication?
a) They remove the need for the receiving service to validate input, since the published schema constrains every request
b) They provide an enforced contract for authenticated, authorized data exchange between services
c) They shorten response time, because services exchange data without passing through an intermediate gateway
d) They keep the payload encrypted inside the consuming application, so plaintext is never handled in memory
 
09. A business continuity plan is being revised to include a cloud backup service alongside the existing on-site copies, and the revision has to state what the service contributes to recovery. What is the critical reason for incorporating it?
a) Recovery capacity scales to the volume being restored, and the copies are held away from the primary site
b) The shared responsibility model transfers the obligation to recover the business to the provider
c) Continuous replication by the provider removes the need to set recovery point and recovery time objectives
d) Provider-side verification of the stored copies, which detects corruption in storage, makes restore testing unnecessary
 
10. Identity management architecture rests on the AAA triad: authentication, authorization and accounting. A design must be able to establish after the fact which identity performed a given privileged operation, and to defend that record if it is challenged.
Which element of the triad carries that requirement, and what must the architecture supply to meet it?
a) Authentication, supported by multifactor verification of the credential
b) Availability, supported by replication of the directory service
c) Accounting, supported by tamper-evident storage of the records
d) Authorization, supported by policy evaluation at the time of request

Answers:

Question: 01
Answer: c
Question: 02
Answer: a
Question: 03
Answer: d
Question: 04
Answer: c
Question: 05
Answer: b
Question: 06
Answer: b
Question: 07
Answer: d
Question: 08
Answer: b
Question: 09
Answer: a
Question: 10
Answer: c

Note: For any error in ISC2 Information Systems Security Architecture Professional (CISSP-ISSAP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.7 / 5 (137 votes)