ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architecture review of a four-tier web application (presentation, business logic, data, and network/infrastructure), the team must align security controls with the Security Chain of Responsibility. Which pairing of control with layer BEST reflects this principle?
Presentation layer - firewall packet filtering; Business logic layer - database backup; Data layer - output encoding; Network layer - user authentication
The Security Chain of Responsibility assigns each layer the controls it can enforce most effectively. The presentation (UI) layer is closest to user input and therefore should implement output encoding to neutralize reflected data. The business logic layer owns application workflows and is the correct place to make authorization decisions based on roles and context. The data layer controls database storage, so transparent encryption of tablespaces or files is its responsibility. Finally, the network/infrastructure layer manages traffic entering or leaving the environment and is the logical point to apply firewall packet filtering. The other pairings mix responsibilities, placing controls in layers that lack the necessary context, access, or capabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Security Chain of Responsibility?
Open an interactive chat with Bash
Why is output encoding necessary at the presentation layer?
Open an interactive chat with Bash
How does transparent encryption work at the data layer?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .