ISC2 CC Security Principles Practice Question
A company stores backup tapes containing customer data in an offsite vault. The security policy requires that if the tapes are lost or stolen, the data cannot be read by unauthorized parties. Which control should the company implement to meet this requirement?
⚠ Common exam trap
The trap here is relying on physical controls like locked cabinets, which fail once the tape leaves the controlled environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encrypt the backup tapes
Encryption protects data confidentiality even when physical media is lost or stolen. By encrypting backup tapes, the company ensures that unauthorized parties cannot read customer data without the decryption keys. Checksums, labels, and locked cabinets may support handling or integrity, but none prevents a thief from reading the tape contents, so encryption is the required control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Encrypt the backup tapes
Why this is correct
Encrypting backup tapes renders the data unreadable without the appropriate keys, even if the physical media is lost or stolen. This directly satisfies the requirement that unauthorized parties cannot read the data. Therefore, encryption is the correct control for protecting data at rest on transported media in this scenario.
- ✗
Label the tapes with a classification marking
Why it's wrong here
Classification labels help personnel handle media according to policy, but they do not stop a thief from reading the data. Labels are administrative aids, not technical protection. Because the requirement focuses on preventing unauthorized reading if tapes are lost or stolen, labeling alone is insufficient and not the correct answer.
- ✗
Store the tapes in a locked cabinet
Why it's wrong here
A locked cabinet provides physical protection at the storage location, but it does not protect data if the tapes are lost or stolen during transport or if the cabinet is breached. The scenario explicitly considers loss or theft, so physical locking alone cannot guarantee the data remains unreadable. Thus it is not the best control.
- ✗
Apply a checksum to each tape
Why it's wrong here
A checksum detects accidental errors or changes in data but does not prevent an unauthorized party from reading the tape contents. It supports integrity checking, not confidentiality. Since the requirement is to keep stolen data unreadable, a checksum does not meet the need and is not the correct control.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.