ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architecture review of a ride-sharing mobile app, you notice the client uploads raw GPS coordinates every five seconds, even when running in the background, to pre-match available rides. Which architectural change most effectively mitigates privacy risks associated with this implicit data collection while still allowing the feature to function?
Perform on-device processing of GPS data and send only coarse, tokenized area identifiers needed for ride matching.
Route location uploads through a separate, dedicated API gateway isolated from other services.
Increase retention of uploaded location records to 90 days to support analytics and fraud investigations.
Protect the GPS payload with TLS 1.3 encryption during transmission to the backend.
Processing the user's precise location locally on the device and transmitting only the minimum necessary information (for example, a coarse-grained or tokenized area identifier) applies the principle of data minimization. By limiting the granularity of the data that leaves the device, the architecture reduces the amount of personally identifiable location information exposed or stored, directly lowering privacy risk while preserving the matching feature. Simply encrypting transmissions protects data in transit but does not reduce what is collected; extending retention increases risk; and using a separate API gateway changes network topology without addressing the privacy issue of collecting fine-grained location data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is data minimization in relation to user privacy?
Open an interactive chat with Bash
How does on-device processing improve privacy?
Open an interactive chat with Bash
What is the difference between TLS encryption and data minimization?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .