ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team must ensure that nightly database backup tapes shipped to a third-party vault cannot be read if they are lost in transit. Which control most directly enforces confidentiality for the data on the tapes?
Encrypt the backups with AES-256 and store the decryption key securely inside the data center.
Mark the tapes "confidential" and ship them only via bonded courier service.
Configure the backup server with RAID-6 to tolerate disk failures.
Apply an SHA-256 hash to each file before shipping.
Encrypting the backup media renders the stored information unintelligible without possession of the decryption key, directly addressing the confidentiality requirement for data at rest as well as while the tapes are in transit. A cryptographic hash provides only integrity verification and does not hide the data itself. Merely labeling the tapes and using a bonded courier is a procedural safeguard that can reduce mishandling but does not technically prevent unauthorized viewing. RAID or other redundancy schemes improve availability and fault tolerance, not confidentiality. Therefore, strong encryption with a separately secured key is the appropriate control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AES-256 encryption?
Open an interactive chat with Bash
Why is an SHA-256 hash not suitable for ensuring confidentiality?
Open an interactive chat with Bash
How does storing the decryption key inside the data center enhance security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .