ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While designing a battery-powered medical implant, your team worries an attacker with physical access could recover the device's AES key by measuring its power usage during firmware updates. Which design decision most directly mitigates this simple power analysis threat?

  • Require mutual TLS for all communications between the implant and external programming devices.

  • Enable hardware write-protection on the flash region that stores the symmetric key material.

  • Switch from 128-bit to 256-bit AES keys to increase resistance against brute-force attacks.

  • Use constant-time cryptographic routines supplemented with data masking to make power consumption independent of secret values.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot