🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization's policy mandates that all payroll data be encrypted at rest. Unfortunately, the legacy UNIX server that hosts the payroll database cannot support any modern filesystem or database-level encryption, and a platform upgrade is at least six months away. As the security practitioner, which action represents the most appropriate compensating control to meet the encryption-at-rest requirement while the legacy system remains in service?

  • Integrate an approved cryptographic library into the payroll application to encrypt sensitive records before they are written to disk.

  • Schedule nightly full backups of the payroll server to encrypted tapes that are stored in an off-site vault.

  • Place the legacy payroll server in an isolated VLAN protected by an additional firewall that only allows traffic from HR workstations.

  • Increase password complexity requirements and enforce a 90-day rotation policy for all payroll system user accounts.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot