nerdexam
(ISC)2

CISSP · Question #567

For the purpose of classification, which of the following is used to divide trust domain and trust boundaries?

The correct answer is A. Network architecture. In security classification, network architecture defines the structural boundaries that separate trust domains and establish trust boundaries within an environment.

Submitted by jian89· Mar 5, 2026Communication and Network Security

Question

For the purpose of classification, which of the following is used to divide trust domain and trust boundaries?

Options

  • ANetwork architecture
  • BIntegrity
  • CIdentity Management (IdM)
  • DConfidentiality management

How the community answered

(17 responses)
  • A
    88% (15)
  • B
    6% (1)
  • D
    6% (1)

Why each option

In security classification, network architecture defines the structural boundaries that separate trust domains and establish trust boundaries within an environment.

ANetwork architectureCorrect

Network architecture defines the physical and logical layout of a network, including segmentation, zones, and perimeters that establish trust domains (groups of entities sharing the same level of trust) and trust boundaries (the points where trust levels change). By designing network segments such as DMZs, internal zones, and external zones, network architecture directly controls where trust is granted or restricted. This structural approach is the foundational mechanism for classifying and enforcing trust relationships across a system.

BIntegrity

Integrity is a security property (ensuring data has not been altered), not a structural mechanism used to divide or classify trust domains and boundaries.

CIdentity Management (IdM)

Identity Management manages authentication and authorization of users and entities, but it operates within trust boundaries rather than defining or dividing the boundaries themselves.

DConfidentiality management

Confidentiality management focuses on protecting data from unauthorized disclosure and is a data-centric control, not a structural mechanism for partitioning trust domains.

Concept tested: Trust domains and boundaries defined by network architecture

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/network-best-practices

Topics

#Network architecture#Trust domains#Security boundaries#Network segmentation

Community Discussion

No community discussion yet for this question.

Full CISSP Practice