Exam
200 Practice Questions & Detailed Answers | Final Exam Test
Bank with Rationales | A+ Graded
Domain: Security Architecture & Design (Questions 145)
1. What is the primary goal of defenseindepth?
A) To rely on a single strong security control
B) To eliminate all threats completely
C) To implement multiple layers of security controls
D) To focus only on network security
Correct Answer: C
Rationale: Defenseindepth uses layered security measures so that if one control fails, others still provide
protection. This approach ensures that no single point of failure compromises the entire system.
Multiple layers address physical, technical, and administrative controls to create redundancy in
protection.
2. Which of the following is the core principle of Zero Trust architecture?
A) Trust all internal traffic and verify external traffic
B) Trust never, always verify
C) Trust only after successful authentication once
D) Trust based on network location
Correct Answer: B
,Rationale: Zero Trust architecture assumes no implicit trust granted to any user or device based solely
on network location (inside vs. outside the corporate perimeter). Every access request must be fully
authenticated, authorized, and encrypted before granting access.
3. Which security model focuses primarily on confidentiality and is commonly used in government and
military systems?
A) Biba Model
B) ClarkWilson Model
C) BellLaPadula Model
D) BrewerNash Model
Correct Answer: C
Rationale: The BellLaPadula model enforces confidentiality using the rules "no read up" (a subject
cannot read an object at a higher classification level) and "no write down" (a subject cannot write to an
object at a lower classification level). This model is designed to prevent unauthorized disclosure of
classified information.
4. Which security model focuses on integrity and prevents unauthorized modification of data?
A) BellLaPadula Model
B) Biba Model
C) BrewerNash Model
D) ClarkWilson Model
Correct Answer: B
,Rationale: The Biba model is the integrity counterpart to BellLaPadula. It enforces "no read down" and
"no write up" to prevent untrusted subjects from modifying trusted objects, ensuring data integrity.
5. The NIST Cybersecurity Framework (CSF) consists of five core functions. Which of the following is NOT
one of these functions?
A) Identify
B) Protect
C) Detect
D) Audit
E) Respond
F) Recover
Correct Answer: D
Rationale: The NIST CSF core functions are Identify, Protect, Detect, Respond, and Recover. Audit is not a
core function but rather a control activity that spans multiple functions.
6. Which NIST Cybersecurity Framework function involves developing and implementing appropriate
safeguards to ensure delivery of critical services?
A) Identify
B) Protect
C) Detect
D) Respond
Correct Answer: B
, Rationale: The Protect function of the NIST CSF involves developing and implementing appropriate
safeguards to ensure delivery of critical infrastructure services. This includes access control, awareness
training, data security, and protective technology.
7. Which SABSA layer is concerned with the business requirements and security policy?
A) Contextual Layer
B) Conceptual Layer
C) Logical Layer
D) Physical Layer
Correct Answer: A
Rationale: SABSA (Sherwood Applied Business Security Architecture) uses a sixlayer model. The
Contextual Layer is the highest level, focusing on business requirements and security policy. It answers
"Why" security is needed from a business perspective.
8. What is the primary purpose of the TOGAF Architecture Development Method (ADM)?
A) To provide a securityspecific architecture framework
B) To develop enterprise architecture through an iterative process
C) To manage risk across the organization
D) To implement technical security controls
Correct Answer: B
Rationale: TOGAF ADM is an iterative process for developing enterprise architecture. It provides a
method for developing and managing the lifecycle of an enterprise architecture, consisting of phases