ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your development team discovers that application audit logs currently record full session tokens, client IPs, and user IDs in plaintext. To minimize the impact of a potential log disclosure without losing the ability to correlate events, which logging adjustment provides the most effective protection?
Increase log retention period to comply with audit requirements
Replace session tokens in the log with a salted hash value generated at runtime
Store logs on an encrypted filesystem with access restricted to administrators
Base64-encode session tokens before writing them to the log
Hashing (ideally with a salt) replaces each session token with an irreversible value before it is written to disk, so the token itself can no longer be replayed if logs are exposed. Because the same token always hashes to the same value during its lifetime, analysts can still correlate related events. Simply Base64-encoding the token offers no real protection because it is easily reversible. Encrypting the log file or its storage medium does add a layer of defense, but insiders or processes with decryption access could still read the raw tokens, and the application would still write secrets to memory and disk. Extending the retention period does nothing to reduce disclosure risk and may increase it by keeping sensitive data longer.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is hashing with a salt used for session token protection?
Open an interactive chat with Bash
What makes Base64 encoding insufficient for security?
Open an interactive chat with Bash
How does encrypting logs compare to hashing session tokens for protection?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .