ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During architecture planning for a SaaS electronic-health-record platform, the risk assessment ranks security objectives as follows: confidentiality - high, integrity - moderate, availability - low. Budget limitations allow funding only one additional control in the first release. Which control should be given the highest priority to address the stated objectives?

  • Deploy an active-active dual-site architecture with automatic fail-over for high availability.

  • Add a global content delivery network (CDN) to improve performance and resiliency.

  • Encrypt all patient data at rest in the database with AES-256 and dedicated key management.

  • Implement a centralized SIEM to collect and correlate security events in real time.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot