ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a design review of a new service-oriented architecture, the team plans to route all inter-service messages through a single, centrally hosted Enterprise Service Bus (ESB) that also performs authentication and authorization. As the security architect, which secure architecture principle is most directly jeopardized, and what design change would best mitigate the concern?
It violates the principle of complete mediation; require the ESB to log every request and response.
It violates the principle of least privilege; add fine-grained role assignments at each service endpoint.
It violates the principle of defense in depth; place a web application firewall in front of the ESB.
It creates a single point of failure; deploy redundant ESB nodes in active-active mode across multiple availability zones.
An ESB can simplify policy enforcement, but concentrating all messaging and security functions in one instance creates a single point of failure. This undermines the secure architecture principle of avoiding single points of failure (resiliency/availability). Deploying multiple ESB instances in an active-active configuration across separate fault domains restores resilience, ensuring that if one instance or site fails, others can continue processing messages. The other choices address important security concepts-least privilege, defense in depth, and complete mediation-but they do not directly resolve the high availability risk introduced by a lone ESB.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Enterprise Service Bus (ESB) in a service-oriented architecture?
Open an interactive chat with Bash
Why is a single point of failure a risk in secure architecture design?
Open an interactive chat with Bash
How does active-active configuration improve system resilience?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .