Try 12 SABSA Foundation sample questions on business-driven security architecture, model layers, attributes, risk alignment, controls, traceability, and assurance.
SABSA Foundation preparation centers on business-driven security architecture: attributes, model layers, traceability, controls, risk alignment, and assurance.
These 12 original questions are a public preview, not official SABSA questions.
Practice option: Sample questions available
Start with the 12 sample questions on this page. Dedicated practice for SABSA Foundation is not currently included as a full web-app practice page; enter your email to get updates when full practice becomes available or expands for this exam.
Need live practice now? See currently available IT Mastery exam pages.
Verify current certification levels, policies, and training requirements with the SABSA certification page .
Topic: business attributes
What is the purpose of security attributes in SABSA-style thinking?
Best answer: B
Explanation: Security attributes translate business needs into qualities the architecture must support, such as confidentiality, availability, integrity, accountability, or resilience.
Topic: traceability
Why is traceability important in security architecture?
Best answer: A
Explanation: Traceability lets reviewers see why a control or architecture decision exists and which business requirement it supports.
Topic: model layers
Which statement best reflects layered architecture reasoning?
Best answer: B
Explanation: Separating layers helps candidates reason from business intent through implementation and operation without mixing every concern at once.
Topic: risk alignment
A business requires continuous online ordering during peak periods. Which security attribute is most directly emphasized?
Best answer: B
Explanation: Continuous service during peak demand is an availability and resilience concern. Other attributes may also matter, but availability is central.
Topic: control selection
Which control decision is strongest?
Best answer: B
Explanation: Security architecture needs context. Controls should be selected because they satisfy traceable requirements in a specific business and technical setting.
Topic: assurance
What does assurance add to security architecture?
Best answer: A
Explanation: Assurance uses evidence, testing, review, monitoring, and governance to support confidence in design and operation.
Topic: stakeholder language
Why should security architecture avoid only technical jargon with executives?
Best answer: A
Explanation: Security architecture must communicate at the right level. Executive conversations often require risk and value framing rather than low-level configuration details.
Topic: architecture scope
Which item is most clearly an architecture concern?
Best answer: A
Explanation: Architecture connects security capabilities and design choices to a business service and its operating context.
Topic: common trap
Which approach is weakest?
Best answer: B
Explanation: SABSA-style security architecture is business-driven. A detached checklist cannot show why controls are needed or whether they fit.
Topic: logical architecture
What belongs in a logical security architecture view?
Best answer: A
Explanation: Logical views describe security services and relationships without forcing one product or physical implementation too early.
Topic: operational view
Why include an operational view?
Best answer: A
Explanation: Operational architecture covers how security capabilities are run, monitored, supported, and improved.
Topic: exam reasoning
When two answer choices both mention controls, which one is usually stronger?
Best answer: B
Explanation: Strong security architecture reasoning ties controls to business context and reviewable evidence, not just product names.