SSCP Systems and Application Security Practice Question
A healthcare organization is developing a mobile application that stores patient data locally on the device. The security team must ensure that if a device is lost or stolen, the data cannot be accessed without the user's authentication. Which of the following controls should be implemented to meet this requirement?
⚠ Common exam trap
Watch out — candidates often confuse data-in-transit protections like certificate pinning with data-at-rest protections, which are needed for lost device scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable full-device encryption and require a strong passcode.
The most direct control to prevent access to locally stored data on a lost or stolen device is full-device encryption tied to a passcode. This ensures that without the correct passcode, the encryption keys cannot be derived, rendering the data unreadable. Other options address different threats such as network interception or reverse engineering, but not data-at-rest confidentiality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use obfuscation to hide the application's code and data structures.
Why it's wrong here
Obfuscation makes reverse engineering more difficult but does not encrypt data. An attacker with physical access to the device can still extract and read the local files. Obfuscation is a defense-in-depth measure, not a primary control for protecting data confidentiality when a device is lost. It fails to meet the requirement.
- ✗
Store all patient data in a remote database and cache nothing locally.
Why it's wrong here
While storing data remotely reduces local exposure, the scenario states that the app stores patient data locally. Changing the architecture may not be feasible, and it does not address the requirement to protect the local data if it must be stored. Also, caching might still occur inadvertently. This option does not directly secure the local data as required.
- ✓
Enable full-device encryption and require a strong passcode.
Why this is correct
Full-device encryption protects all data at rest, including the application's local storage. When combined with a strong passcode, the encryption keys are derived from the passcode, so without it the data remains inaccessible. This directly satisfies the requirement that lost or stolen devices do not expose patient data, as the attacker cannot decrypt the storage without the passcode.
- ✗
Implement certificate pinning for all API communications.
Why it's wrong here
Certificate pinning ensures that the app only trusts a specific certificate for its backend API, preventing man-in-the-middle attacks on data in transit. It does not protect data stored locally on the device. If the device is lost, an attacker could still read the local files. Therefore, it does not meet the requirement for protecting data at rest.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.