ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architectural risk assessment of a new three-tier web application, you learn that the distributed in-memory cache keeps customer personally identifiable information (PII) in clear text. A stated security requirement mandates encryption of all sensitive data at rest. Which architectural change best ensures compliance with this requirement while maintaining cache performance?
Configure the cache to evict entries rapidly by setting a very short time-to-live (TTL) for PII objects.
Limit cache access to application servers by tightening network ACLs around the cache cluster.
Enable mutual TLS for all traffic between application servers and cache nodes.
Encrypt PII in the application before caching it, using keys stored in an HSM (envelope encryption).
Storing PII in clear text within any data store-including an in-memory cache that may write to disk or be exposed through memory disclosure attacks-violates the encryption-at-rest requirement. Encrypting the data before putting it into the cache and protecting the keys in a hardware security module (HSM) guarantees that the information is encrypted wherever the cache stores it (memory snapshots, persistence files, or replicas). Network ACLs or mutual TLS only protect data in transit, not at rest inside the cache. Simply shortening the time-to-live still leaves the data unencrypted for its lifetime. Therefore, pre-encrypting the PII with keys secured in an HSM is the most direct and effective mitigation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an HSM and why is it used in encryption?
Open an interactive chat with Bash
How does envelope encryption ensure data security?
Open an interactive chat with Bash
Why doesn’t mutual TLS or ACLs satisfy the encryption-at-rest requirement?
Open an interactive chat with Bash
What is envelope encryption?
Open an interactive chat with Bash
What is an HSM, and how does it improve security?
Open an interactive chat with Bash
How does encryption-at-rest differ from encryption-in-transit?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .