CISSP · Question #567
For the purpose of classification, which of the following is used to divide trust domain and trust boundaries?
The correct answer is A. Network architecture. In security classification, network architecture defines the structural boundaries that separate trust domains and establish trust boundaries within an environment.
Question
For the purpose of classification, which of the following is used to divide trust domain and trust boundaries?
Options
- ANetwork architecture
- BIntegrity
- CIdentity Management (IdM)
- DConfidentiality management
How the community answered
(17 responses)- A88% (15)
- B6% (1)
- D6% (1)
Why each option
In security classification, network architecture defines the structural boundaries that separate trust domains and establish trust boundaries within an environment.
Network architecture defines the physical and logical layout of a network, including segmentation, zones, and perimeters that establish trust domains (groups of entities sharing the same level of trust) and trust boundaries (the points where trust levels change). By designing network segments such as DMZs, internal zones, and external zones, network architecture directly controls where trust is granted or restricted. This structural approach is the foundational mechanism for classifying and enforcing trust relationships across a system.
Integrity is a security property (ensuring data has not been altered), not a structural mechanism used to divide or classify trust domains and boundaries.
Identity Management manages authentication and authorization of users and entities, but it operates within trust boundaries rather than defining or dividing the boundaries themselves.
Confidentiality management focuses on protecting data from unauthorized disclosure and is a data-centric control, not a structural mechanism for partitioning trust domains.
Concept tested: Trust domains and boundaries defined by network architecture
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/network-best-practices
Topics
Community Discussion
No community discussion yet for this question.