Try 12 SABSA Practitioner sample questions on applied security architecture design, business attributes, traceability, risk scenarios, assurance planning, and design tradeoffs.
SABSA Practitioner preparation should feel scenario-based: choose the architecture response that preserves business traceability, risk alignment, assurance, and operating fit.
These 12 original questions are a public preview, not official SABSA questions.
Practice option: Sample questions available
Start with the 12 sample questions on this page. Dedicated practice for SABSA Practitioner is not currently included as a full web-app practice page; enter your email to get updates when full practice becomes available or expands for this exam.
Need live practice now? See currently available IT Mastery exam pages.
Verify current certification levels, policies, and training requirements with the SABSA certification page .
Topic: requirement traceability
A payment service needs fast checkout, fraud control, audit evidence, and privacy protection. What should the architect do first?
Best answer: B
Explanation: Practitioner-level reasoning starts from business drivers and attributes before control or product selection.
Topic: design tradeoff
Which answer best handles a conflict between usability and stronger authentication?
Best answer: C
Explanation: Applied architecture deals with tradeoffs. The strongest answer balances attributes, risk, user impact, and assurance.
Topic: assurance plan
What should an assurance plan include?
Best answer: A
Explanation: Assurance requires evidence over time, not a one-time statement that controls exist.
Topic: risk scenario
A supplier API outage could prevent customers from completing orders. Which architecture concern is most direct?
Best answer: B
Explanation: The scenario affects service availability and resilience. The architecture response should consider dependency, failover, monitoring, and recovery.
Topic: logical design
Which design step should come before selecting a specific identity product?
Best answer: A
Explanation: Logical architecture clarifies what the identity service must do before a physical product is selected.
Topic: architecture views
Why use multiple views for one security architecture?
Best answer: A
Explanation: Business, conceptual, logical, physical, component, and operational views support different decisions while preserving traceability.
Topic: control fit
An encryption control is proposed for sensitive records. What question is most important?
Best answer: A
Explanation: Encryption is not automatically sufficient. Architecture must consider data classification, threat path, key management, access, operations, and evidence.
Topic: stakeholder mapping
Which stakeholder question is strongest?
Best answer: A
Explanation: Practitioner work must clarify ownership, operation, evidence, and acceptance of residual risk.
Topic: attribute profile
What is an attribute profile used for?
Best answer: A
Explanation: Attribute profiles help translate business needs into security qualities that can be designed and reviewed.
Topic: common trap
Which response is weakest when a control fails assurance testing?
Best answer: C
Explanation: Purchased controls still need assurance. Failed evidence should trigger review and remediation, not denial.
Topic: operating model
What makes a security architecture operationally realistic?
Best answer: A
Explanation: A design that cannot be operated and monitored will not deliver reliable security outcomes.
Topic: scenario decision
A regulator asks for evidence that privileged access is controlled. What is the best architecture response?
Best answer: A
Explanation: Evidence should connect requirement, design, operation, monitoring, review, and control effectiveness.