|
via Udemy |
Go to Course: https://www.udemy.com/course/issap-information-systems-security-architecture-qa-test/
ISSAP Information Systems Security Architecture Professional Exam Practice Test The Information Systems Security Architecture Professional (ISSAP) is a CISSP who specializes in designing security solutions and providing management with risk-based guidance to meet organizational goals. ISSAPs facilitate the alignment of security solutions within the organizational context (e.g., vision, mission, strategy, policies, requirements, change, and external factors).The CISSP-ISSAP is an appropriate credential if the candidate is a chief security architect or analyst. Typically, the candidate works as an independent consultant or in a similar capacity. As the architect, candidates play a key role in the information security department.ISSAP Exam Domain:-Domain 1. Architect for Governance, Compliance and Risk ManagementDetermine legal, regulatory, organizational and industry requirementsManage RiskDomain 2. Security Architecture ModelingIdentify security architecture approachVerify and validate design (e.g., Functional Acceptance Testing (FAT), regression)Domain 3. Infrastructure Security ArchitectureDevelop infrastructure security requirementsDesign defense-in-depth architectureSecure shared services (e.g., wireless, e-mail, Voice over Internet Protocol (VoIP), Unified Communications (UC), Domain Name System (DNS), Network Time Protocol (NTP))Integrate technical security controlsDesign and integrate infrastructure monitoringDesign infrastructure cryptographic solutionsDesign secure network and communication infrastructure (e.g., Virtual Private Network (VPN), Internet Protocol Security (IPsec), Transport Layer Security (TLS))Evaluate physical and environmental security requirementsDomain 4. Identity and Access Management (IAM) ArchitectureDesign identity management and lifecycleDesign access control management and lifecycleDesign identity and access solutionsDomain 5. Architect for Application SecurityIntegrate Software Development Life Cycle (SDLC) with application security architecture (e.g., Requirements Traceability Matrix (RTM), security architecture documentation, secure coding)Determine application security capability requirements and strategy (e.g., open source, Cloud Service Providers (CSP), Software as a Service (SaaS)/Infrastructure as a Service (IaaS)/ Platform as a Service (PaaS) environments)Identify common proactive controls for applications (e.g., Open Web Application Security Project (OWASP))Domain 6. Security Operations ArchitectureGather security operations requirements (e.g., legal, compliance, organizational, and business requirements)Design information security monitoring (e.g., Security Information and Event Management (SIEM), insider threat, threat intelligence, user behavior analytics, Incident Response (IR) procedures)Design Business Continuity (BC) and resiliency solutionsValidate Business Continuity Plan (BCP)/Disaster Recovery Plan (DRP) architectureDesign Incident Response (IR) management