ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your organization is deploying a new SIEM that will ingest security event data in near real-time from application servers located in branch offices connected over the public Internet. To prevent both eavesdropping on the log contents and the insertion of forged log messages while they are in transit, which log-transfer design should you recommend?

  • Batch log files hourly, compress them, and upload via FTP over an IP-whitelisted channel to the SIEM.

  • Attach an HMAC to each log entry but forward them over unencrypted TCP to minimize overhead.

  • Use RFC 5425 syslog over TLS with mutual certificate authentication between every server and the SIEM.

  • Send standard UDP syslog on port 514 across a dedicated management VLAN to limit exposure.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot