ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During an architectural risk assessment of a new three-tier web application, you learn that the distributed in-memory cache keeps customer personally identifiable information (PII) in clear text. A stated security requirement mandates encryption of all sensitive data at rest. Which architectural change best ensures compliance with this requirement while maintaining cache performance?

  • Configure the cache to evict entries rapidly by setting a very short time-to-live (TTL) for PII objects.

  • Limit cache access to application servers by tightening network ACLs around the cache cluster.

  • Enable mutual TLS for all traffic between application servers and cache nodes.

  • Encrypt PII in the application before caching it, using keys stored in an HSM (envelope encryption).

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot