ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization classifies approved press releases as public information, indicating that their disclosure carries no confidentiality risk. You must specify baseline security controls for the cloud storage bucket that will contain only these files. Which requirement best addresses the realistic protection needs for this data without imposing unnecessary overhead?
Require each file to be digitally signed or hashed so any unauthorized modification can be detected during retrieval.
Label all objects as Confidential and prevent them from being exported outside the corporate network.
Encrypt every file in the bucket with AES-256 and store the keys in a hardware security module.
Configure the bucket so that only authenticated users in the marketing role can download the files.
Because approved press releases are already intended for unrestricted public distribution, confidentiality controls such as strong encryption, restrictive access controls, or a "Confidential" label are unnecessary and would add needless complexity. Public data can still be a target for defacement, so ensuring that stored objects are digitally signed or hashed lets the organization detect unauthorized modification and preserve integrity-typically the only security objective that still applies to publicly available information. Therefore, requiring an integrity-verification mechanism is the most appropriate and efficient control. The other options focus on confidentiality and overly restrictive handling that is not warranted for public data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is integrity important for public data like press releases?
Open an interactive chat with Bash
What is a digital signature or hash, and how do they work?
Open an interactive chat with Bash
Why aren't encryption or restrictive access controls needed for public data?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .