SABSA Chartered Foundation (SCF) Certificate
SABSA CHARTERED FOUNDATION (SCF) CERTIFICATE | COMPLETE EXAM 2026/2027
| QUESTIONS AND 100% VERIFIED ANSWERS | PASS GUARANTEE
SABSA Chartered Foundation (SCF) Certificate
1. What does the acronym SABSA stand for?
A. Standard Applied Business Systems Architecture
B. Secure Architecture for Business Systems Assurance
C. Structured Analysis for Business Security Assurance
D. Sherwood Applied Business Security Architecture
2. Who are recognised as the original co-developers of the SABSA
methodology?
A. Andrew Clark, Bruce Schneier, and David Lynas
B. John Zachman, Andrew Clark, and David Lynas
C. John Sherwood, Andrew Clark, and David Lynas
D. John Sherwood, David Lynas, and Ross Anderson
3. SABSA is best described as a framework that is primarily driven by:
A. Technology vendor specifications
B. Business requirements and risk
C. Regulatory compliance checklists alone
D. Network topology constraints
4. Which other well-known framework structure heavily influenced the
layered design of the SABSA Matrix?
Page 1 of 37
, SABSA Chartered Foundation (SCF) Certificate
A. TOGAF ADM
B. ITIL service lifecycle
C. COBIT process model
D. The Zachman Framework
5. SABSA is best classified as a:
A. Software product for firewall configuration
B. Methodology for developing risk-driven enterprise security
architectures
C. Single technical control standard
D. Penetration testing methodology
6. Which organisation is responsible for the stewardship and certification
scheme of SABSA today?
A. ISO
B. NIST
C. The Open Group
D. The SABSA Institute
7. SABSA is fundamentally described as being:
A. Dependent on a specific firewall vendor
B. Tied exclusively to Microsoft technologies
C. Only applicable to cloud environments
D. Technology-neutral and vendor-independent
8. Which of the following best describes the overall goal of the SABSA
approach?
A. To standardise programming languages used in security tools
B. To replace the need for any IT governance
C. To eliminate all business risk entirely
D. To ensure security services are designed to support and enable
business objectives
9. SABSA differs from many traditional security frameworks primarily
because it:
A. Ignores risk assessment entirely
B. Starts from business requirements rather than starting from
technical controls
Page 2 of 37
, SABSA Chartered Foundation (SCF) Certificate
C. Is limited to financial services organisations
D. Only focuses on physical security
10. The 'Chartered' designation in SABSA certifications (e.g., SCF) primarily
signifies:
A. Membership of a national engineering institute
B. A formally recognised, examined level of competence in the SABSA
methodology
C. An accounting qualification
D. A legal license to practise law
11. Which of these is NOT one of the recognised SABSA certification levels?
A. SABSA Certified Auditor (SCAu)
B. SABSA Chartered Practitioner (SCP)
C. SABSA Chartered Master (SCM)
D. SABSA Chartered Foundation (SCF)
12. SABSA can best be applied to which of the following scopes?
A. Only mobile application development
B. Enterprise-wide security architecture as well as solution-level
architectures
C. Only single-server hardening projects
D. Only wireless network design
13. In SABSA, a Business Attribute is best defined as:
A. A cryptographic algorithm specification
B. A network port number
C. A property or characteristic that the business requires of a system
or process, expressed in business language
D. A line item in a firewall rule base
14. The primary purpose of Business Attributes Profiling is to:
A. Design the physical cabling layout
B. Generate a list of software licences
C. Translate business requirements into a traceable set of attributes
that drive architecture decisions
D. Select an antivirus vendor
Page 3 of 37
, SABSA Chartered Foundation (SCF) Certificate
15. Which of the following is an example of a SABSA Business Attribute?
A. 'Cost-effective'
B. 'VLAN 10'
C. 'TCP/IP'
D. 'RSA-2048'
16. SABSA groups Business Attributes into categories such as governance,
risk, and:
A. Only hardware specifications
B. Legal and regulatory, technical strategy, and organisational
C. Only sales targets
D. Only marketing objectives
17. A key benefit of using Business Attributes is that they:
A. Replace the need for a security policy
B. Remove the need for any risk assessment
C. Provide a common language between business stakeholders and
technical architects
D. Automatically configure network devices
18. Attributes in the SABSA profile are typically expressed as:
A. Adjectives or short descriptive phrases meaningful to business
stakeholders
B. Regular expressions
C. Binary machine code
D. SQL query statements
19. Traceability in the Business Attributes Profile means that each attribute
should be linked back to:
A. A specific business requirement or driver
B. A specific server rack number
C. A random number generator seed
D. An arbitrary colour code
20. Which of the following best describes a 'measure' associated with a
Business Attribute?
A. The brand name of the software vendor
B. A metric used to assess whether the attribute has been achieved
Page 4 of 37
SABSA CHARTERED FOUNDATION (SCF) CERTIFICATE | COMPLETE EXAM 2026/2027
| QUESTIONS AND 100% VERIFIED ANSWERS | PASS GUARANTEE
SABSA Chartered Foundation (SCF) Certificate
1. What does the acronym SABSA stand for?
A. Standard Applied Business Systems Architecture
B. Secure Architecture for Business Systems Assurance
C. Structured Analysis for Business Security Assurance
D. Sherwood Applied Business Security Architecture
2. Who are recognised as the original co-developers of the SABSA
methodology?
A. Andrew Clark, Bruce Schneier, and David Lynas
B. John Zachman, Andrew Clark, and David Lynas
C. John Sherwood, Andrew Clark, and David Lynas
D. John Sherwood, David Lynas, and Ross Anderson
3. SABSA is best described as a framework that is primarily driven by:
A. Technology vendor specifications
B. Business requirements and risk
C. Regulatory compliance checklists alone
D. Network topology constraints
4. Which other well-known framework structure heavily influenced the
layered design of the SABSA Matrix?
Page 1 of 37
, SABSA Chartered Foundation (SCF) Certificate
A. TOGAF ADM
B. ITIL service lifecycle
C. COBIT process model
D. The Zachman Framework
5. SABSA is best classified as a:
A. Software product for firewall configuration
B. Methodology for developing risk-driven enterprise security
architectures
C. Single technical control standard
D. Penetration testing methodology
6. Which organisation is responsible for the stewardship and certification
scheme of SABSA today?
A. ISO
B. NIST
C. The Open Group
D. The SABSA Institute
7. SABSA is fundamentally described as being:
A. Dependent on a specific firewall vendor
B. Tied exclusively to Microsoft technologies
C. Only applicable to cloud environments
D. Technology-neutral and vendor-independent
8. Which of the following best describes the overall goal of the SABSA
approach?
A. To standardise programming languages used in security tools
B. To replace the need for any IT governance
C. To eliminate all business risk entirely
D. To ensure security services are designed to support and enable
business objectives
9. SABSA differs from many traditional security frameworks primarily
because it:
A. Ignores risk assessment entirely
B. Starts from business requirements rather than starting from
technical controls
Page 2 of 37
, SABSA Chartered Foundation (SCF) Certificate
C. Is limited to financial services organisations
D. Only focuses on physical security
10. The 'Chartered' designation in SABSA certifications (e.g., SCF) primarily
signifies:
A. Membership of a national engineering institute
B. A formally recognised, examined level of competence in the SABSA
methodology
C. An accounting qualification
D. A legal license to practise law
11. Which of these is NOT one of the recognised SABSA certification levels?
A. SABSA Certified Auditor (SCAu)
B. SABSA Chartered Practitioner (SCP)
C. SABSA Chartered Master (SCM)
D. SABSA Chartered Foundation (SCF)
12. SABSA can best be applied to which of the following scopes?
A. Only mobile application development
B. Enterprise-wide security architecture as well as solution-level
architectures
C. Only single-server hardening projects
D. Only wireless network design
13. In SABSA, a Business Attribute is best defined as:
A. A cryptographic algorithm specification
B. A network port number
C. A property or characteristic that the business requires of a system
or process, expressed in business language
D. A line item in a firewall rule base
14. The primary purpose of Business Attributes Profiling is to:
A. Design the physical cabling layout
B. Generate a list of software licences
C. Translate business requirements into a traceable set of attributes
that drive architecture decisions
D. Select an antivirus vendor
Page 3 of 37
, SABSA Chartered Foundation (SCF) Certificate
15. Which of the following is an example of a SABSA Business Attribute?
A. 'Cost-effective'
B. 'VLAN 10'
C. 'TCP/IP'
D. 'RSA-2048'
16. SABSA groups Business Attributes into categories such as governance,
risk, and:
A. Only hardware specifications
B. Legal and regulatory, technical strategy, and organisational
C. Only sales targets
D. Only marketing objectives
17. A key benefit of using Business Attributes is that they:
A. Replace the need for a security policy
B. Remove the need for any risk assessment
C. Provide a common language between business stakeholders and
technical architects
D. Automatically configure network devices
18. Attributes in the SABSA profile are typically expressed as:
A. Adjectives or short descriptive phrases meaningful to business
stakeholders
B. Regular expressions
C. Binary machine code
D. SQL query statements
19. Traceability in the Business Attributes Profile means that each attribute
should be linked back to:
A. A specific business requirement or driver
B. A specific server rack number
C. A random number generator seed
D. An arbitrary colour code
20. Which of the following best describes a 'measure' associated with a
Business Attribute?
A. The brand name of the software vendor
B. A metric used to assess whether the attribute has been achieved
Page 4 of 37