ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a design review for a battery-powered IoT sensor network, you must select a mechanism to protect data in transit between hundreds of constrained sensors and a central gateway. Which option BEST applies the economy-of-mechanism principle to maximize both security assurance and resource efficiency on the sensors?
Implement full TLS with X.509 certificates, online OCSP checks, and elliptic-curve key exchange for every connection.
Embed an XML parser in every sensor and secure messages with WS-Security-based XML signatures.
Use Datagram TLS (DTLS) with pre-shared keys so each sensor performs only symmetric-key operations.
Add a proprietary encryption layer on top of standard TLS to provide "defense in depth."
The economy-of-mechanism principle favors security mechanisms that are as simple as possible because they are easier to analyze and typically consume fewer CPU cycles, memory, and power-critical factors for constrained IoT nodes. Pre-shared-key (PSK)-based Datagram TLS leverages a well-vetted standard, avoids complex certificate handling, and keeps message headers small, meeting confidentiality and integrity goals while minimizing computational and bandwidth overhead.
Using X.509 certificates with full public-key operations or adding XML-based WS-Security introduces significant code size, processing, and energy costs, violating both simplicity and efficiency goals. Designing a proprietary encryption layer on top of TLS also complicates the stack, increasing attack surface and maintenance effort without clear benefit. Therefore, adopting lightweight DTLS with PSK best embodies economy of mechanism and resource efficiency.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Datagram TLS (DTLS) and how does it differ from standard TLS?
Open an interactive chat with Bash
Why are pre-shared keys preferred in constrained IoT networks?
Open an interactive chat with Bash
What is the economy-of-mechanism principle in security design?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .