ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a forensic investigation of an unauthorized database dump, the response team discovers that every application node keeps its audit records in plain-text files on the local disk and developers can alter or delete those files at will. Which control, if it had been implemented, would have most directly preserved accountability for the actions that led to the breach?

  • Requiring multi-factor authentication for all privileged user accounts

  • Centralized, write-once log collection stored on a server where only security administrators have append-only rights

  • Encrypting local audit files with the application's TLS certificate

  • Scheduling weekly differential backups of the application servers

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot