ExamGecko
Question list
Search
Search

Related questions











Question 564 - 312-50v12 discussion

Report
Export

As a cybersecurity analyst for SecureNet, you are performing a security assessment of a new mobile payment application. One of your primary concerns is the secure storage of customer data on the device. The application stores sensitive information such as credit card details and personal identification numbers (PINs) on the device. Which of the following measures would best ensure the security of this data?

A.
Implement biometric authentication for app access.
Answers
A.
Implement biometric authentication for app access.
B.
Encrypt all sensitive data stored on the device.
Answers
B.
Encrypt all sensitive data stored on the device.
C.
Enable GPS tracking for all devices using the app.
Answers
C.
Enable GPS tracking for all devices using the app.
D.
Regularly update the app to the latest version.
Answers
D.
Regularly update the app to the latest version.
Suggested answer: B

Explanation:

Encrypting all sensitive data stored on the device is the best measure to ensure the security of this data, because it protects the data from unauthorized access or disclosure, even if the device is lost, stolen, or compromised. Encryption is a process of transforming data into an unreadable format using a secret key or algorithm. Only authorized parties who have the correct key or algorithm can decrypt and access the data. Encryption can be applied to data at rest, such as files or databases, or data in transit, such as network traffic or messages. Encryption can prevent attackers from stealing or tampering with the customer data stored on the device, such as credit card details and PINs, which can cause financial or identity fraud.

The other options are not as effective or sufficient as encryption for securing the customer data stored on the device. Implementing biometric authentication for app access may provide an additional layer of security, but it does not protect the data from being accessed by other means, such as malware, physical access, or backup extraction. Enabling GPS tracking for all devices using the app may help locate the device in case of loss or theft, but it does not prevent the data from being accessed by unauthorized parties, and it may also pose privacy risks. Regularly updating the app to the latest version may help fix bugs or vulnerabilities, but it does not guarantee the security of the data, especially if the app does not use encryption or other security features.

Reference:

Securely Storing Data | Security.org

Data Storage Security: 5 Best Practices to Secure Your Data

M9: Insecure Data Storage | OWASP Foundation

asked 18/09/2024
Dominique Dusabe
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first