Courseiva

SSCP Systems and Application Security Practice Question

A developer is building a mobile banking application and wants to ensure that if an attacker gains physical access to a rooted or jailbroken device, the application's sensitive data stored locally cannot be easily read. The developer decides to use the secure storage provided by the mobile operating system. Which of the following BEST describes the protection offered by this secure storage?

⚠ Common exam trap

The trap here is treating application sandboxing as sufficient protection, when a rooted or jailbroken device allows an attacker to bypass sandbox restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data is encrypted with a hardware-backed key stored in a secure element or trusted execution environment.

Mobile operating systems provide secure storage such as iOS Keychain and Android Keystore, which encrypt data with hardware-backed keys stored in a secure element or trusted execution environment. This protects sensitive data even on rooted or jailbroken devices because the key cannot be easily extracted. Password-derived keys, obfuscation, and sandbox permissions do not provide equivalent protection against a privileged attacker.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data is encrypted with a hardware-backed key stored in a secure element or trusted execution environment.

    Why this is correct

    Mobile OS secure storage, such as iOS Keychain or Android Keystore, uses hardware-backed keys in a secure element or trusted execution environment. The key material is protected from software attacks, and even on a rooted or jailbroken device, extracting the key is significantly harder. This matches the protection the developer seeks for locally stored sensitive data.

  • ✗

    Data is encrypted with a key derived from the user's login password, which is never stored on the device.

    Why it's wrong here

    Deriving a key solely from a user password without storing any verifier would require the user to enter the password every time data is accessed and would make password recovery impossible. More importantly, the scenario asks about OS-provided secure storage, which uses hardware-backed keys, not password-derived keys. This option mischaracterizes how secure storage works.

  • ✗

    Data is stored in a hidden directory that is inaccessible to other applications due to sandbox permissions.

    Why it's wrong here

    Application sandboxing prevents other apps from reading the directory, but on a rooted or jailbroken device an attacker with elevated privileges can bypass sandbox restrictions. The scenario explicitly assumes the device is compromised, so sandbox permissions alone are insufficient. The data must be encrypted with hardware-backed keys to remain protected.

  • ✗

    Data is obfuscated using a proprietary algorithm that changes with each application release to prevent reverse engineering.

    Why it's wrong here

    Obfuscation is not encryption and provides only a weak barrier against a determined attacker. A rooted or jailbroken device allows dynamic instrumentation, so the obfuscated data can be observed at runtime. This approach does not provide the cryptographic protection offered by OS secure storage and would not satisfy the requirement to protect sensitive local data.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.