SABSA FINAL TEST 2026 QUESTIONS WITH CORRECT
ANSWERS GRADED A+
● 2. Checks authorisation. Answer: Which 2 actions does the Relying Party perform in the
trust broker model?
● 2. Claims authority. Answer: Which two (2) actions does the Claimant perform in the trust
brokering model
● Component Layer, People (Who) Column. Answer: Where in the SABSA Architecture
Matrix is Personnel Management Tools & Standards located?
● Conceptual layer, Motivation (Why) column. Answer: Where in the SABSA Architecture
Matrix are Risk Management Objectives and enablement and control objectives located?
● Trust is a Relational business attribute not a technical one.. Answer: What type of
attribute is Trust?
● Domain Policies. Answer: What objectives/outcomes exist at the Logical Architecture layer
in the Motivation (Why) column of the SABSA Matrix?
● Domain Definitions; Inter-domain associations & interactions. Answer: What
objectives/outcomes exist at the Logical Architecture layer in the Location (Where) column of
the SABSA Matrix?
● Business Risk - Opportunities & Threats Inventory. Answer: What objectives/outcomes
exist at the Contextual Architecture layer in the Motivation (Why) column of the SABSA
Matrix?
● Policy Architecture. Answer: What objectives/outcomes exist at the Conceptual
Architecture layer in the Motivation (Why) column of the SABSA Matrix?
● Business Attributes Profile. Answer: What objectives/outcomes exist at the Conceptual
Architecture layer in the Assets (What) column of the SABSA Matrix?
● The Trustee role is RESPONSIBLE for the performance of assets (attributes) within a
specific domain. Trustee is a delegated authority role. Consults domain owner on risk
appetite.. Answer: What is the main difference between the Owner role and Trustee role in
the SABSA Governance model?
, ● It is the heart of the SABSA methodology. The Business Attributes Profile is the
'requirements engineering' technique that makes SABSA truly unique and provides
linkage between business requirements and technology / process design.. Answer:
Describe the concept of the SABSA Business Attributes Profile
● 4. Blended Approach. Answer: What are the four (4) SABSA start-up approaches?
● 2. Domain Policy. Answer: List the two high-level categories of the SABSA Policy
Framework
● False. Each domain should enforce its own security policy, independently of other
domains. Trust between domains will have different registration authorities.. Answer:
TRUE or FALSE: Trust between domains is also constant
● A security domain is a set of elements subject to a common security policy defined
and owned by a single policy authority.. Answer: What is the definition of a Security
Domain according to SABSA?
● security services. Answer: Relating to Infrastructure Layer Domains, _____________
_______________ are deployed in each technical domain to meet the policy, control &
enablement objectives of that domain
● Elements exist in logical domains not tied to specific physical locations. Answer:
Describe the Design Phase Logical Layer
● Elements exist in a specific physical domain and location. Answer: Describe the
Design Phase Physical Layer
● Protocols. Answer: Describe the Design Phase Component Layer
● Concerned with management processes & activities. Answer: Describe the Design
Phase Management Layer
● ** It builds on their strengths by adding security in a fully aligned way. Answer:
SABSA fills the gaps by being _______ and _________
● - Define contextual & conceptual security architecture. Answer: Define the ITIL Service
Lifecycle of Service Strategy
● - Define Logical, Physical & Component security Architeture. Answer: Define the ITIL
Service Lifecycle of Service Design
● Implementation. Answer: Define the ITIL Service Lifecycle of Service Transition
ANSWERS GRADED A+
● 2. Checks authorisation. Answer: Which 2 actions does the Relying Party perform in the
trust broker model?
● 2. Claims authority. Answer: Which two (2) actions does the Claimant perform in the trust
brokering model
● Component Layer, People (Who) Column. Answer: Where in the SABSA Architecture
Matrix is Personnel Management Tools & Standards located?
● Conceptual layer, Motivation (Why) column. Answer: Where in the SABSA Architecture
Matrix are Risk Management Objectives and enablement and control objectives located?
● Trust is a Relational business attribute not a technical one.. Answer: What type of
attribute is Trust?
● Domain Policies. Answer: What objectives/outcomes exist at the Logical Architecture layer
in the Motivation (Why) column of the SABSA Matrix?
● Domain Definitions; Inter-domain associations & interactions. Answer: What
objectives/outcomes exist at the Logical Architecture layer in the Location (Where) column of
the SABSA Matrix?
● Business Risk - Opportunities & Threats Inventory. Answer: What objectives/outcomes
exist at the Contextual Architecture layer in the Motivation (Why) column of the SABSA
Matrix?
● Policy Architecture. Answer: What objectives/outcomes exist at the Conceptual
Architecture layer in the Motivation (Why) column of the SABSA Matrix?
● Business Attributes Profile. Answer: What objectives/outcomes exist at the Conceptual
Architecture layer in the Assets (What) column of the SABSA Matrix?
● The Trustee role is RESPONSIBLE for the performance of assets (attributes) within a
specific domain. Trustee is a delegated authority role. Consults domain owner on risk
appetite.. Answer: What is the main difference between the Owner role and Trustee role in
the SABSA Governance model?
, ● It is the heart of the SABSA methodology. The Business Attributes Profile is the
'requirements engineering' technique that makes SABSA truly unique and provides
linkage between business requirements and technology / process design.. Answer:
Describe the concept of the SABSA Business Attributes Profile
● 4. Blended Approach. Answer: What are the four (4) SABSA start-up approaches?
● 2. Domain Policy. Answer: List the two high-level categories of the SABSA Policy
Framework
● False. Each domain should enforce its own security policy, independently of other
domains. Trust between domains will have different registration authorities.. Answer:
TRUE or FALSE: Trust between domains is also constant
● A security domain is a set of elements subject to a common security policy defined
and owned by a single policy authority.. Answer: What is the definition of a Security
Domain according to SABSA?
● security services. Answer: Relating to Infrastructure Layer Domains, _____________
_______________ are deployed in each technical domain to meet the policy, control &
enablement objectives of that domain
● Elements exist in logical domains not tied to specific physical locations. Answer:
Describe the Design Phase Logical Layer
● Elements exist in a specific physical domain and location. Answer: Describe the
Design Phase Physical Layer
● Protocols. Answer: Describe the Design Phase Component Layer
● Concerned with management processes & activities. Answer: Describe the Design
Phase Management Layer
● ** It builds on their strengths by adding security in a fully aligned way. Answer:
SABSA fills the gaps by being _______ and _________
● - Define contextual & conceptual security architecture. Answer: Define the ITIL Service
Lifecycle of Service Strategy
● - Define Logical, Physical & Component security Architeture. Answer: Define the ITIL
Service Lifecycle of Service Design
● Implementation. Answer: Define the ITIL Service Lifecycle of Service Transition