ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a threat-modeling workshop you learn that the application occasionally writes a temporary file containing a user's full name, personal e-mail address, and passport number. Using a common four-tier scheme (Public, Internal, Confidential, Restricted), which classification and protections are most appropriate?
Classify as Public; default directory permissions are adequate.
Classify as Restricted; enforce encryption at rest and in transit and securely delete the file when finished.
Classify as Internal; limit viewing to employees, but encryption is optional.
Classify as Confidential; protect with encryption but allow normal deletion procedures.
All three data elements are personally identifiable information, and the passport number is sensitive government-issued ID. Most enterprise schemes place such highly sensitive PII in the Restricted tier, which carries the most stringent controls: strong access control, encryption at rest and in transit, and secure deletion once no longer needed. Labeling it Public or Internal violates policy, and treating it merely as Confidential understates the risk and may omit mandatory controls required for Restricted data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does passport information require Restricted classification?
Open an interactive chat with Bash
What does secure deletion entail for Restricted data?
Open an interactive chat with Bash
How does encryption at rest and in transit protect Restricted data?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .