CYBERSECURITY ARCHITECTURE AND
ENGINEERING OA STUDY GUIDE 2026 FULL
PRACTICE QUESTIONS WITH STEP-BY-STEP
SECURITY SOLUTIONS
◉ A security analyst is performing a security assessment and is
recommending ways to manage risk relating to personnel. Which of
the following should the analyst recommend? Select 3 answers.
A - Mandatory vacation
B - Least privilege
C - Email protection
D - Auditing requirements
Answer: A, B & D; Mandatory Vacation, Least Privilege, and Auditing
Requirements
Mandatory vacation is one way of helping to manage personnel risk.
An administrator forces employees to take their vacation time,
during which someone else fulfills their duties.
The principle of least privilege is a practice in which an
administrator only gives users account privileges they need to
,perform their duties. This practice serves in various capacities, such
as helping against both insider threats and compromised accounts.
Auditing requirements describe the capability for auditing account
creation, modification, deletion, and account activity for all accounts.
Auditing is a way to help manage personnel risk.
Email protection is a technical control, although it does help to
safeguard against attacks against personnel.
◉ A security engineer is considering moving his organization's IT
services to the cloud but is concerned whether the vendor they are
considering will be in business on an ongoing basis. What type of
vendor assessment is this?
A - Vendor viability
B - Source code escrow
C - Vendor lock-in
D - Vendor lockout
Answer: A - Vendor Viability
Vendor viability considers whether a vendor will remain in business
on an ongoing basis, that they have a viable and in-demand product,
and the financial means to stay afloat.
,Source code escrow is a copy of vendor-developed source code
provided to a trusted third party in case a vendor ceases business.
Vendor lock-in occurs when a customer is completely dependent on
a vendor for products or services, as switching is either impossible
or would result in substantial complexity and costs.
Vendor lockout occurs when a vendor develops its product in such a
way that makes it inoperable with other products, and the ability to
integrate it with other vendor products is not a feasible option, or it
does not exist.
◉ A security manager is standing up a risk management program at
a company. What should the security manager set up that might be
considered the most recognized output?
A - Processes
B - Key Performance Indicators
C - Key Risk Indicators
D - Risk Register
Answer: D - Risk Register
The risk register can be the most recognized output of the risk
management program. It includes metadata such as threat, impact,
likelihood, plan, and risk level.
, Processes are an important component of risk, but the risk register
would be the most recognized output. Processes drive consistency
and reliability.
Key Performance Indicators (KPIs) are a formal mechanism
designed to measure the performance of a program against desired
goals.
Key Risk Indicators (KRIs) are closely related to KPIs. By analyzing
KPIs, trends may appear and be indicative of additional risk items
and should be further analyzed and addressed proactively.
◉ A security architect for an organization is conducting an internal
assessment on current policies, processes, and procedures to ensure
protection for the businesses' technology and financial operations.
Which of the following would be best suited to support this
assessment?
A - STAR
B - SOC
C - ISO
D - CMMC
Answer: B - SOC
ENGINEERING OA STUDY GUIDE 2026 FULL
PRACTICE QUESTIONS WITH STEP-BY-STEP
SECURITY SOLUTIONS
◉ A security analyst is performing a security assessment and is
recommending ways to manage risk relating to personnel. Which of
the following should the analyst recommend? Select 3 answers.
A - Mandatory vacation
B - Least privilege
C - Email protection
D - Auditing requirements
Answer: A, B & D; Mandatory Vacation, Least Privilege, and Auditing
Requirements
Mandatory vacation is one way of helping to manage personnel risk.
An administrator forces employees to take their vacation time,
during which someone else fulfills their duties.
The principle of least privilege is a practice in which an
administrator only gives users account privileges they need to
,perform their duties. This practice serves in various capacities, such
as helping against both insider threats and compromised accounts.
Auditing requirements describe the capability for auditing account
creation, modification, deletion, and account activity for all accounts.
Auditing is a way to help manage personnel risk.
Email protection is a technical control, although it does help to
safeguard against attacks against personnel.
◉ A security engineer is considering moving his organization's IT
services to the cloud but is concerned whether the vendor they are
considering will be in business on an ongoing basis. What type of
vendor assessment is this?
A - Vendor viability
B - Source code escrow
C - Vendor lock-in
D - Vendor lockout
Answer: A - Vendor Viability
Vendor viability considers whether a vendor will remain in business
on an ongoing basis, that they have a viable and in-demand product,
and the financial means to stay afloat.
,Source code escrow is a copy of vendor-developed source code
provided to a trusted third party in case a vendor ceases business.
Vendor lock-in occurs when a customer is completely dependent on
a vendor for products or services, as switching is either impossible
or would result in substantial complexity and costs.
Vendor lockout occurs when a vendor develops its product in such a
way that makes it inoperable with other products, and the ability to
integrate it with other vendor products is not a feasible option, or it
does not exist.
◉ A security manager is standing up a risk management program at
a company. What should the security manager set up that might be
considered the most recognized output?
A - Processes
B - Key Performance Indicators
C - Key Risk Indicators
D - Risk Register
Answer: D - Risk Register
The risk register can be the most recognized output of the risk
management program. It includes metadata such as threat, impact,
likelihood, plan, and risk level.
, Processes are an important component of risk, but the risk register
would be the most recognized output. Processes drive consistency
and reliability.
Key Performance Indicators (KPIs) are a formal mechanism
designed to measure the performance of a program against desired
goals.
Key Risk Indicators (KRIs) are closely related to KPIs. By analyzing
KPIs, trends may appear and be indicative of additional risk items
and should be further analyzed and addressed proactively.
◉ A security architect for an organization is conducting an internal
assessment on current policies, processes, and procedures to ensure
protection for the businesses' technology and financial operations.
Which of the following would be best suited to support this
assessment?
A - STAR
B - SOC
C - ISO
D - CMMC
Answer: B - SOC