ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A development team is adding real-time location tracking to a new fitness app that periodically uploads GPS coordinates to the provider's cloud for route analytics and social sharing. To reduce the privacy risk to users while still meeting the functional requirement to show routes on a map, which architectural control provides the most effective mitigation?

  • Encrypt each GPS coordinate in transit using TLS 1.3 to prevent eavesdropping between the device and cloud.

  • Prompt users for explicit consent every time the app is opened before activating the GPS sensor and uploading data.

  • Define user-configured 'privacy zones' that omit location collection when the device is within a designated radius of home or work.

  • Aggregate GPS samples locally and upload only a down-sampled path with reduced spatial precision (e.g., street-level segments instead of exact coordinates).

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot