Architecture & Engineering | Verified Q&A with Rationales | Pass
Guaranteed – A+ Graded | 250 Practice Questions
Questions 1–250
1. The NIST Cybersecurity Framework (CSF) consists of five core
functions. Which of the following is NOT one of these functions? E)
Respond F) Recover
A) Identify
B) Protect
C) Detect
D) Audit
Answer D: Audit
,Rationale: The NIST CSF core functions are Identify, Protect, Detect,
Respond, and Recover; Audit is a control activity that spans multiple
functions.
2. Which NIST Cybersecurity Framework function involves
developing and implementing appropriate safeguards to ensure
delivery of critical services?
A) Identify
B) Protect
C) Detect
D) Respond
Answer B: Protect
Rationale: The Protect function limits the impact of a potential
cybersecurity event through identity management, access control,
awareness training, data security, and protective technology.
3. In the SABSA framework, which layer addresses the business
requirements and defines the business drivers?
A) Contextual Architecture
,B) Conceptual Architecture
C) Logical Architecture
D) Physical Architecture
Answer A: Contextual Architecture
Rationale: SABSA uses a layered approach; the Contextual
Architecture layer defines business context, drivers, and objectives
that drive security architecture decisions.
4. The TOGAF Architecture Development Method (ADM) includes all
of the following phases EXCEPT:
A) Architecture Vision
B) Business Architecture
C) Technology Architecture
D) Security Implementation
Answer D: Security Implementation
Rationale: TOGAF ADM phases include Architecture Vision, Business
Architecture, Information Systems Architecture, and Technology
Architecture; security is embedded throughout rather than as a
separate phase.
, 5. Which security architecture framework is specifically designed for
information security and is based on a six-layer model?
A) TOGAF
B) Zachman Framework
C) SABSA
D) COBIT
Answer C: SABSA
Rationale: SABSA (Sherwood Applied Business Security Architecture)
is specifically designed for information security using a six-layer
model (Contextual, Conceptual, Logical, Physical, Component,
Operational).
6. A security team notices traffic coming from a country where the
organization does not have any business operations. What could
this indicate?
A) High call volume
B) Odd network traffic
C) Geographic anomalies
D) Unauthorized changes