ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During requirements elicitation for a fitness-tracking app that stores users' geolocation data in the cloud, the security engineer must capture a privacy requirement addressing cross-border transfers. Which requirement best satisfies this concern?

  • Encrypt all geolocation data at rest using AES-256 before storing it in any cloud region.

  • Automatically purge geolocation records after 30 days of user inactivity.

  • Require multi-factor authentication for users who access their historical geolocation data.

  • Ensure all geolocation data is stored within the region where it was collected unless explicit legal basis for transfer is documented.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot