CERTIFICATION EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. Which statement best describes the primary purpose of the
SABSA framework?
A. To provide a technical architecture for implementing firewalls and
intrusion detection systems
B. To provide a business-driven framework for developing and
managing enterprise security architecture
C. To define a mandatory set of cybersecurity controls for every
organization
D. To replace enterprise architecture frameworks such as TOGAF
Answer: B. To provide a business-driven framework for developing
and managing enterprise security architecture
Rationale: SABSA is fundamentally business-driven. It connects
business requirements and risk to security architecture, services,
processes, and technologies. It is not simply a catalog of technical
controls or a product-implementation methodology. Its central purpose
is to ensure that security architecture supports business objectives and
delivers measurable business value.
2. An organization is developing a security architecture for a new
digital banking platform. Senior management states that the most
important requirement is customer trust and uninterrupted
1
,availability of critical banking services. Which SABSA principle
should guide the architect's initial work?
A. Begin by selecting security technologies
B. Begin by identifying the organization's business requirements and
attributes
C. Begin by configuring network segmentation
D. Begin by selecting encryption algorithms
Answer: B. Begin by identifying the organization's business
requirements and attributes
Rationale: SABSA begins with business requirements rather than
technology. Customer trust, availability, regulatory compliance,
confidentiality, and other business concerns must be translated into
security requirements and architectural attributes before specific
technologies or controls are selected.
3. In the SABSA model, which question is most closely associated
with the contextual level?
A. How will security controls be technically implemented?
B. What security services should be deployed?
C. Why does the business need security, and what are its business
requirements?
D. Which physical devices should implement the architecture?
Answer: C. Why does the business need security, and what are its
business requirements?
Rationale: The contextual layer establishes the broad business context
for security architecture. It identifies business requirements, business
assets, risks, opportunities, and security-related business needs. It
provides the foundation for progressively more detailed architectural
decisions.
2
,4. Which sequence correctly represents the SABSA architectural
layers from the highest-level business perspective toward
implementation?
A. Operational → Conceptual → Contextual → Component → Logical
→ Physical
B. Contextual → Conceptual → Logical → Physical → Component →
Operational
C. Physical → Logical → Conceptual → Contextual → Operational →
Component
D. Contextual → Physical → Logical → Operational → Conceptual →
Component
Answer: B. Contextual → Conceptual → Logical → Physical →
Component → Operational
Rationale: SABSA uses a layered architecture model that progressively
transforms business requirements into implementable security
solutions. The contextual layer establishes business requirements, the
conceptual layer develops the security architecture concept, the logical
layer defines services and structures, the physical layer determines
technologies and mechanisms, the component layer identifies actual
products and components, and the operational layer addresses
deployment and management.
5. Which SABSA layer is primarily concerned with defining the
logical security services required by the enterprise?
A. Contextual
B. Conceptual
C. Logical
D. Component
3
, Answer: C. Logical
Rationale: The logical layer translates conceptual security
requirements into logical security services and structures. It is
concerned with what security services are needed and how those
services should logically interact, without prematurely committing to
specific products or technologies.
6. A security architect recommends a particular firewall vendor
before determining the organization's security requirements. What
SABSA principle is being violated?
A. Business-driven architecture
B. Operational monitoring
C. Attribute profiling
D. Security-service management
Answer: A. Business-driven architecture
Rationale: SABSA discourages technology-first security design.
Architecture should be driven by business requirements, risks, and
security attributes. Selecting a firewall vendor before understanding
the business problem creates the risk of designing around a technology
rather than designing a security capability that actually supports the
business.
7. What is the primary purpose of security attributes in SABSA?
A. To identify specific hardware components
B. To express business-driven security requirements in measurable terms
C. To replace risk assessments
D. To identify employees who are responsible for security
4