SABSA COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
● SABSA architectural model. Answer: A model that aligns the security program with the
business mission, providing a framework for developing and implementing effective security
solutions.
● compromise of hardware that processes encryption. Answer: The act of exploiting
vulnerabilities in hardware that handles encryption, which can be achieved through
techniques such as timing and power analysis, out-of-band communications, brute force
attacks, or credential management.
● mitigate compromise of operating system security during initialization process.
Answer: The process of reducing the risk of compromising the security of an operating system
during its initialization phase. This can be accomplished through techniques like secure boot
or Trusted Computing Base (TCB).
● compromise of building management systems (BMS). Answer: The act of gaining
unauthorized access to building management systems, often due to vulnerabilities in insecure
protocols or the use of open source software.
● early attacks using buffer overflows. Answer: Historically, attacks that exploited buffer
overflow vulnerabilities to execute arbitrary code or propagate worms. Nowadays, similar
attacks can be performed through email links, leading to remote code execution or worm
infections.
● designing a backup solution for critical files. Answer: The process of creating a backup
strategy for important files, ensuring compliance with the Recovery Time Objective (RTO) to
minimize downtime and data loss in the event of a failure.
● Type 1 hypervisor. Answer: Also known as a bare metal hypervisor, it is a virtualization
technology that runs directly on the host system's hardware, allowing multiple operating
systems to run simultaneously.
● outgoing email containing key words or suspicious string. Answer: An email that
triggers alerts due to the presence of specific keywords or suspicious strings, often blocked by
a Data Loss Prevention (DLP) system to prevent sensitive information from being leaked.
QUESTIONS AND SOLUTIONS GRADED A+
● SABSA architectural model. Answer: A model that aligns the security program with the
business mission, providing a framework for developing and implementing effective security
solutions.
● compromise of hardware that processes encryption. Answer: The act of exploiting
vulnerabilities in hardware that handles encryption, which can be achieved through
techniques such as timing and power analysis, out-of-band communications, brute force
attacks, or credential management.
● mitigate compromise of operating system security during initialization process.
Answer: The process of reducing the risk of compromising the security of an operating system
during its initialization phase. This can be accomplished through techniques like secure boot
or Trusted Computing Base (TCB).
● compromise of building management systems (BMS). Answer: The act of gaining
unauthorized access to building management systems, often due to vulnerabilities in insecure
protocols or the use of open source software.
● early attacks using buffer overflows. Answer: Historically, attacks that exploited buffer
overflow vulnerabilities to execute arbitrary code or propagate worms. Nowadays, similar
attacks can be performed through email links, leading to remote code execution or worm
infections.
● designing a backup solution for critical files. Answer: The process of creating a backup
strategy for important files, ensuring compliance with the Recovery Time Objective (RTO) to
minimize downtime and data loss in the event of a failure.
● Type 1 hypervisor. Answer: Also known as a bare metal hypervisor, it is a virtualization
technology that runs directly on the host system's hardware, allowing multiple operating
systems to run simultaneously.
● outgoing email containing key words or suspicious string. Answer: An email that
triggers alerts due to the presence of specific keywords or suspicious strings, often blocked by
a Data Loss Prevention (DLP) system to prevent sensitive information from being leaked.