Free ISC2 Certified Information Systems Security Professional (CISSP) practice — 6 questions on Security Architecture and Engineering, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Security Architecture and Engineering
An engineer must provide remote monitoring dashboards fed by telemetry from an isolated ICS/SCADA network, but under no circumstances can any traffic be permitted to travel from the corporate/monitoring segment back into the ICS network. Which control BEST satisfies this requirement?
A data diode enforces true one-way, hardware-based data flow, making it physically impossible for traffic to travel from the monitoring segment back into the ICS network. This is the NIST SP 800-82 recommended control when strict unidirectional flow is mandatory.
Question 2 of 6 · Security Architecture and Engineering
A payment-processing system must ensure that only validated 'well-formed transactions' can modify account balances, that duties for initiating, approving, and reconciling transactions are performed by different roles, and that every change to protected data passes through an authorized transformation procedure. Which security model BEST describes this design?
Clark-Wilson explicitly defines constrained data items (CDIs), transformation procedures (TPs) enforcing well-formed transactions, and certification/enforcement rules mandating separation of duties — exactly matching every requirement in the scenario.
Question 3 of 6 · Security Architecture and Engineering
A new data center's occupied server room requires an automatic fire-suppression agent that leaves no residue, is safe for personnel present during discharge, does not deplete the ozone layer, and will not damage electronic hardware. Which agent should be specified?
Clean agents such as FK-5-1-12 (Novec 1230) are non-conductive, leave no residue, are rated safe for occupied spaces at design concentrations, and are ozone-friendly — meeting every stated requirement while protecting equipment.
Question 4 of 6 · Security Architecture and Engineering
An organization operates a cluster of application servers performing high-volume signing and encryption operations. Policy requires that private keys be generated, stored, and used only within a FIPS 140-2 Level 3 validated boundary, and that the cryptographic device be shared across multiple servers over a network connection. Which solution satisfies this requirement?
A network-attached HSM is a dedicated appliance validated to FIPS 140-2 Level 3 or higher, purpose-built to generate/store keys and perform crypto operations at scale, and can be shared across multiple servers over the network — matching every requirement stated.
Question 5 of 6 · Security Architecture and Engineering
A government agency must select an encryption algorithm and key length to protect classified documents that must remain confidential for a minimum of 30 years, in alignment with Commercial National Security Algorithm (CNSA) Suite guidance for long-term cryptographic protection. Which choice BEST meets this requirement?
CNSA Suite guidance mandates AES-256 for symmetric encryption of information requiring decades-long confidentiality, providing margin against both classical brute-force advances and future cryptanalytic threats.
Question 6 of 6 · Security Architecture and Engineering
A security analyst demonstrates that encrypting data with two sequential 56-bit DES keys (2DES) does not provide the expected 112-bit effective key strength, because an attacker can precompute and store intermediate encryption and decryption results, then match them to recover both keys in roughly 2^57 operations. Which attack does this describe?
The meet-in-the-middle attack exploits double encryption by computing forward encryptions from the plaintext and backward decryptions from the ciphertext, then matching intermediate values — defeating the expected security gain of key-length doubling, exactly as described.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.