ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a security assessment of a cloud-based HR application, you learn that employee salary data is sent to an external payroll processor over the public Internet. Which control would best ensure confidentiality of that data while it is in transit?
Require multi-factor authentication for all payroll processor user accounts.
Perform daily file integrity monitoring using cryptographic hashes.
Provision redundant network circuits between the HR application and the payroll processor.
Establish Transport Layer Security (TLS) 1.2 or higher encryption for all sessions between the systems.
Encrypting the communications channel with a current version of Transport Layer Security protects the salary information from disclosure to unauthorized parties as it traverses untrusted networks, directly addressing confidentiality. Multi-factor authentication strengthens user identity proofing but does not prevent interception of the data stream itself. File integrity monitoring verifies that stored data has not been altered, serving integrity rather than confidentiality. Redundant network links improve availability but leave the information readable if captured in transit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Transport Layer Security (TLS)?
Open an interactive chat with Bash
Why is TLS preferred for confidentiality over multi-factor authentication?
Open an interactive chat with Bash
How does file integrity monitoring differ from encryption?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .