Courseiva
easyMultiple Choice

SSCP Practice Question: Deploying a new mobile application that handles…

A company is deploying a new mobile application that handles sensitive customer data. Which practice BEST ensures data confidentiality on the device?

⚠ Common exam trap

ISC2 often tests the distinction between access control (screen lock) and data protection (encryption), leading candidates to choose a strong passcode as the best practice for confidentiality, when encryption with a derived key is the actual requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt all sensitive data stored on the device using a key derived from the user's passcode.

Encrypting sensitive data with a key derived from the user's passcode ensures that even if the device is lost or stolen, the data remains unreadable without the passcode. This approach leverages the user's secret to protect confidentiality at rest, which is a fundamental principle of mobile data protection. Technologies like iOS Data Protection and Android File-Based Encryption use similar key derivation from the lock screen credential to encrypt app-specific data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require a strong screen lock passcode.

    Why it's wrong here

    A screen lock passcode gates device unlock but leaves app data readable once the device is unlocked or if the passcode is bypassed, so it does not protect the stored customer data itself. It is tempting because it is a mandatory baseline control, and it would be correct for reducing risk of casual physical access.

  • ✗

    Disable cloud backups for the app.

    Why it's wrong here

    Disabling cloud backups stops data leaving the device, but the sensitive data still sits unencrypted on local storage, so confidentiality on the device is not ensured. It is tempting because it limits exposure through backup services, and it would be correct when the requirement is preventing data residency or third-party storage.

  • ✓

    Encrypt all sensitive data stored on the device using a key derived from the user's passcode.

    Why this is correct

    Deriving the encryption key from the user's passcode means data at rest is unreadable without that secret, so a lost or stolen device exposes nothing. This directly satisfies the confidentiality requirement for sensitive customer data stored on the device.

  • ✗

    Use app sandboxing to isolate app data from other apps.

    Why it's wrong here

    Sandboxing isolates the app's data from other apps, yet it does not protect that data if the device is lost, rooted or compromised, so confidentiality of the stored customer data is not assured. It is tempting because sandboxing is a genuine mobile security control, and it would be correct for preventing inter-app data leakage.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.