3.0 Security Architecture and Engineering CISSP Practice Quiz
104 exam-style questions covering 13% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A regional bank's architecture review board is finalizing the security model for a new core banking platform. Executives need a risk-based explanation for secure design principles. Which response best aligns with secure engineering practice?
- A. Use threat modeling during requirements and architecture to identify assets, trust boundaries, misuse cases, and likely attack paths
- B. Disable secure error handling so failures bubble up unhandled
- C. Give developers and ops the same broad standing access to production
- D. Pick a complex design to signal sophistication to stakeholders
Secure design begins early enough to influence requirements and architecture rather than discovering major threats after deployment. This is the correct answer.
A pharmaceutical lab is reviewing the security architecture of an instrument-control system for a new facility. A security assurance review must address secure design principles. What should the security professional recommend?
- A. Design components to fail securely when dependencies, authorization checks, or validation services are unavailable
- B. Use a single broad production role for both developers and operators
- C. Add complexity to a design as a signal of sophistication
- D. Bolt on controls after go-live without updating requirements
Fail-secure behavior prevents failures from creating unintended access or unsafe states. This is the correct answer.
A federal agency is selecting cryptographic primitives for a system handling controlled unclassified information. The security architect must make a design decision involving secure design principles. What is the best recommendation?
- A. Trust any device that has reached the internal network with no further verification
- B. Apply least privilege so each subject, service, and component receives the minimum access needed for its function
- C. Turn off exception handling so production failures are visible
- D. Grant developers and operators identical, unrestricted production rights
Least privilege reduces blast radius and limits the damage from compromised accounts or components. This is the correct answer.
A defense contractor is selecting hardware roots of trust for a classified computing platform. A proposed solution creates risk around secure design principles. Which design change best addresses the concern?
- A. Skip secure error handling to make failures more obvious to operators
- B. Use segregation of duties so no single role can initiate, approve, and conceal a high-risk action
- C. Issue developers identical production privileges to operations staff
- D. Select more complex options to display engineering depth
Segregation of duties reduces fraud and misuse by separating conflicting responsibilities. This is the correct answer.
A regional credit union is reviewing security architecture for a new branch-of-the-future kiosk platform. The engineering team asks for CISSP-level guidance on secure design principles. Which approach is most appropriate?
- A. Grant developers full production privileges identical to operators
- B. Document shared responsibility boundaries when a design uses cloud or outsourced services
- C. Choose a complex pattern over a simpler one to look more sophisticated
- D. Apply controls retroactively without revisiting the design baseline
Shared responsibility clarifies which party operates and verifies each control. This is the correct answer.
A children's hospital is designing the architecture for a new patient-facing mobile platform. An architecture review identifies a weakness in secure design principles. Which action should be prioritized?
- A. Bolt controls onto a deployed system without revising requirements
- B. Skip device verification once a workload is on the internal network
- C. Use defense in depth with layered preventive, detective, and corrective controls
- D. Disable error suppression so all failures propagate to users
Layered controls reduce reliance on a single safeguard and improve resilience when one layer fails. This is the correct answer.
A regional utility is designing security controls for a new SCADA-to-IT integration zone. Executives need a risk-based explanation for secure design principles. Which response best aligns with secure engineering practice?
- A. Trust internal-network devices implicitly with no further validation
- B. Disable structured error handling so all errors surface verbosely
- C. Keep designs simple and small enough to be reviewed, tested, and operated reliably
- D. Drop separation of duties between developers and operators in production
Complexity increases the chance of hidden security defects and operational mistakes. This is the correct answer.
A SaaS provider is hardening its multi-tenant control plane against side-channel and noisy-neighbor attacks. The engineering team asks for CISSP-level guidance on secure design principles. Which approach is most appropriate?
- A. Choose architectural complexity to impress reviewers
- B. Add controls post-launch without revisiting the original architecture
- C. Treat being inside the perimeter as evidence the device is trusted
- D. Configure secure defaults so new systems start in a hardened state without requiring administrators to disable unsafe options
Secure defaults reduce exposure from misconfiguration and rushed deployments. This is the correct answer.
Key Terms in This Domain
- SOC 2: Service Organization Controls report on security/availability/confidentiality
- Cold Site: Bare facility without hardware/data: slowest to bring online
- Secure Coding: Practices that prevent common vulnerabilities (input validation, output encoding)
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- Due Diligence: Ongoing effort to investigate, assess, and verify controls and risks
- Risk Mitigation: Apply controls to reduce likelihood or impact
- ISO 27001: International standard for an information security management system (ISMS)
- Data Custodian: Technical role implementing controls (backups, access enforcement)
- Scoping: Removing controls that do not apply to a system
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/security-architecture-and-engineering/
<a href="https://quizbuffet.com/isc2-cissp/security-architecture-and-engineering/">CISSP (ISC2) Security Architecture and Engineering practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 2.0 Asset Security
- 4.0 Communication and Network Security
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
- 8.0 Software Development Security
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.