ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While documenting security objectives for a cloud-based patient portal that stores protected health information (PHI), which of the following security controls most directly addresses the confidentiality requirement of the CIA triad for this system's data?
Deploy redundant web servers across multiple availability zones to avoid downtime
Encrypt the PHI at rest using FIPS 140-validated modules and require TLS for all data in transit
Digitally sign every transaction record to detect any unauthorized modification
Perform weekly full backups to a geographically separate data center for disaster recovery
Confidentiality is concerned with preventing unauthorized disclosure of information. Encrypting PHI both at rest and in transit ensures that even if storage media are lost or network traffic is intercepted, the data remain unintelligible to anyone without the appropriate cryptographic keys. Role-based access controls help limit access but do not protect data if it is intercepted, digital signatures are mainly an integrity measure, and redundancy or backups relate to availability. Therefore, employing strong, validated encryption mechanisms is the control that most directly fulfills the confidentiality objective.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the CIA Triad in security?
Open an interactive chat with Bash
What are FIPS 140-validated modules?
Open an interactive chat with Bash
Why is encryption necessary for PHI?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .