Actual Exam 2026/2027 Complete Exam-Style Questions
with Detailed Rationales | 100% Verified | Pass
Guaranteed – A+ Graded
Security Architecture Fundamentals
Q1: A security architect is reviewing an enterprise’s structural blueprint to ensure all
business perspectives align with security requirements. Which framework organizes this into
intersecting rows of business context and columns of specific stakeholder views?
A. NIST Cybersecurity Framework
B. Zachman Framework [CORRECT]
C. ISO 27001
D. COBIT
Correct Answer: B
Rationale: This choice is correct because the Zachman Framework is specifically designed as
an enterprise architecture ontology that maps business perspectives against specific
stakeholder views, ensuring comprehensive alignment.
Q2: When designing a security architecture from the top down, starting with business goals
and deriving security requirements, which methodology is the architect most likely
applying?
A. SABSA (Sherwood Applied Business Security Architecture) [CORRECT]
B. Penetration testing
C. Vulnerability scanning
D. Reverse engineering
Correct Answer: A
Rationale: The best answer is SABSA. This matches the principle of a business-driven, top-
down approach to security architecture, ensuring that every security control directly
supports a specific business objective.
Q3: A security architect is designing a defence-in-depth strategy for a new hybrid cloud
environment. Which combination of controls best represents this principle?
A. Relying solely on a single, highly advanced cloud-native firewall.
B. Implementing network segmentation, host-based intrusion detection, and strict identity
and access management. [CORRECT]
C. Encrypting data at rest but leaving data in transit unencrypted to improve performance.
D. Using the same administrative password across all on-premises and cloud servers.
Correct Answer: B
Rationale: This choice is correct because defence-in-depth requires multiple, overlapping
layers of security controls (network, host, and identity) so that if one layer fails, others
remain to protect the asset.
,Q4: A company experiences a ransomware attack that encrypts its customer database,
making it temporarily unavailable. Which core security principle has been primarily
violated?
A. Confidentiality
B. Integrity
C. Availability [CORRECT]
D. Non-repudiation
Correct Answer: C
Rationale: This aligns with the CIA triad, where availability ensures that systems and data
are accessible to authorized users when needed. Ransomware directly disrupts this
accessibility.
Q5: Which of the following best describes the difference between security governance and
security management?
A. Governance sets the strategic direction and policies, while management executes the
day-to-day operations to meet those goals. [CORRECT]
B. Governance handles firewall configurations, while management writes the security
policies.
C. Governance is solely the responsibility of the IT department, while management involves
the board of directors.
D. There is no practical difference; the terms are completely interchangeable.
Correct Answer: A
Rationale: The best answer is that governance sets the strategic direction and policies, while
management executes day-to-day operations. This distinction ensures that high-level
business objectives are properly translated into actionable security tasks.
Q6: An organization is adopting a new enterprise architecture framework to ensure IT
investments directly support business strategy. Which framework is most widely recognized
for this specific business-IT alignment?
A. TOGAF (The Open Group Architecture Framework) [CORRECT]
B. STRIDE
C. Diamond Model of Intrusion Analysis
D. Kill Chain
Correct Answer: A
Rationale: This choice is correct because TOGAF is explicitly designed to align enterprise IT
architecture with business goals, providing a comprehensive method and set of tools for
developing that architecture.
Q7: During the design phase of a new application, the team uses a methodology to identify
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation
of Privilege. What is this process called?
A. Vulnerability scanning
B. STRIDE threat modeling [CORRECT]
C. Penetration testing
D. Risk acceptance
Correct Answer: B
, Rationale: This matches the principle of proactive threat modeling. STRIDE is a well-
established framework used by architects and developers to systematically categorize and
address potential security threats during the design phase.
Q8: A company installs a system that automatically locks a user’s account after five failed
login attempts. What type of security control is this?
A. Detective
B. Preventive [CORRECT]
C. Corrective
D. Compensating
Correct Answer: B
Rationale: The best answer is preventive. This control is designed to stop a security incident
(a brute-force attack) from occurring in the first place, rather than just detecting it after the
fact or correcting it afterward.
Q9: A financial analyst is granted access only to the specific accounting software modules
required to perform their daily job functions, and nothing more. This is an example of:
A. Separation of duties
B. Principle of least privilege [CORRECT]
C. Mandatory access control
D. Job rotation
Correct Answer: B
Rationale: This choice is correct because the principle of least privilege dictates that users
should only be granted the minimum levels of access—or permissions—necessary to
perform their legitimate job functions.
Q10: To prevent fraud, a company requires that the employee who approves purchase
orders cannot be the same employee who processes the payments. This is an
implementation of:
A. Dual control
B. Separation of duties [CORRECT]
C. Least privilege
D. Need to know
Correct Answer: B
Rationale: This aligns with the security principle of separation of duties, which divides critical
tasks among multiple people to prevent a single individual from having the ability to both
commit and conceal fraudulent activities.
Q11: When classifying data, which category typically requires the highest level of protection
due to the severe reputational and financial damage its unauthorized disclosure would
cause?
A. Public
B. Internal Use Only
C. Confidential / Restricted [CORRECT]
D. Archived
Correct Answer: C