Security Architecture and Engineering
CISSP · 39 questions
- A public-lobby kiosk in city hall was joined to the domain as a Domain Admin account “so Windows updates keep working.” What redesign best applies least privilege?
- Election-results uploads currently depend on a single perimeter firewall between the upload server and the internet. What architecture change best reduces single-control dependence?
- A new resident-services portal grants guest access to all modules whenever the identity provider is unreachable. What secure-design change should the architect require?
- In the municipal ERP, the same accounts-payable clerk can create a new vendor record and approve that vendor’s payment. Which design change best applies separation of duties?
- Remote assessors historically received broad trust to every sensitive appraisal app once their VPN connected. What access design best aligns with zero-trust principles?
- A city is building a resident AI chatbot that will process service requests containing personal data. Which secure-design principle should be baked into the project from the first architecture reviews?
- A military-adjacent emergency operations center must prevent staff with lower clearances from reading higher-classified briefings. Which classic access model’s confidentiality rules best match that goal?
- Water-quality lab instruments must reject lower-integrity telemetry that could corrupt validated sensor readings. Which classic model’s integrity focus best guides that design?
- Architects designing a multilevel public-safety records system must choose a classic model based on protection goals. When the dominant requirement is stopping unauthorized disclosure across clearance levels, which selection is most appropriate?
- A grant requirement states the city must "protect Criminal Justice Information in transit." Which control set best follows from that stated requirement?
- Legacy court case-management software cannot enforce MFA natively, yet remote clerks must keep using it. What is the most appropriate response?
- A proposal would require hardware security tokens for every anonymous brochure PDF on the parks website. What principle should guide a more appropriate control decision?
- Detective laptops must bind full-disk encryption keys to evidence of platform integrity before unlocking. Which capability best supports that design?
- A custom GIS plugin repeatedly corrupts neighboring processes by writing into their memory spaces. Which operating-system capability should architects insist on to contain that class of failure?
- An evidence-management system must cryptographically protect stored body-worn camera video at rest. What should architects treat as a required information-system capability?
- Thick-client tax software caches credentials on clerk workstations, and the backend database grants a single service account rights far beyond its job. What is the best remediation focus?
- A wastewater plant's PLC network was flat-bridged to city Wi-Fi "for convenience," exposing control traffic to the corporate wireless. What architectural response is most appropriate?
- The city is moving online permitting to a SaaS platform. Which statement best reflects how shared responsibility changes versus on-premises hosting?
- Smart parking sensors and edge gateways were deployed without a reliable patch or certificate-update channel. What risk assessment conclusion is most accurate?
- A 311 rewrite uses microservices, containers, and serverless functions with APIs left wide open between services. Which security concern should architects address first among those patterns?
- Election-night tabulation virtual machines share hypervisors with public web servers, and a research HPC cluster adds further multi-tenant exposure. What architectural concern is most critical?
- A parking-pay mobile app includes a homegrown cryptographic module that invents its own unreviewed network protocol. What is the primary architectural vulnerability?
- A city discovers dozens of TLS certificates for public portals with no inventory, no owner, and no scheduled rotation. Which cryptographic lifecycle action should the security architect prioritize first?
- County IT must encrypt multi-terabyte nightly backups for cold storage and separately assert agency identity when calling a partner court API. Which crypto method pairing best fits those two use cases?
- Two municipal court case-management systems must authenticate each other with mutual TLS. What PKI capability is most essential for that design?
- A city plans to encrypt archival tax records that must remain confidential for several decades. Which approach best reflects algorithm agility and emerging quantum awareness?
- An auditor asks whether the city can explain how brute-force, man-in-the-middle, and side-channel attacks threaten its deployed cryptography. What is the best demonstration of that understanding?
- A municipal payment portal uses a well-regarded cipher suite, yet testers recover plaintext via a padding-oracle style flaw and weak random number generation for nonces. Where should remediation focus?
- After a city Active Directory compromise, responders find reused NTLM hashes, forged Kerberos tickets, and ransomware staging. Which engineering focus best addresses the crypto and authentication-material risks highlighted by those attack methods?
- Facilities proposes placing a new network closet directly under a restroom drain line to shorten cable runs. What site-design response is most appropriate?
- A county is fitting out a municipal server room. Which control set best reflects appropriate facility engineering for that space?
- Digital evidence lockers and offline backup media for the police department currently sit on open shelves in a shared admin office. What facility control change is most appropriate?
- A riverside 911 communications facility sits in a floodplain with a history of utility outages. Which facility-planning emphasis is most critical?
- City hall needs a public lobby for visitors and badge-only work areas for records clerks handling sensitive files. How should facility controls be designed?
- A CAD replacement project skipped security requirements analysis and plans to "bolt on" controls the week before go-live. What lifecycle guidance should the security architect insist on?
- Before accepting a vendor-built citizen portal, the city must confirm security requirements were actually met. Which lifecycle activity does that describe?
- The city is decommissioning an old ERP. Which retirement actions are most essential from a security perspective?
- A new municipal records system is entering architectural design. What must occur regarding security before that design hardens?
- A small parks-and-recreation registration app is being given a highly custom, complex single sign-on stack that few staff understand. What secure-engineering response is most appropriate?