SSCP Systems and Application Security Practice Question
A healthcare organization stores protected health information on a database server. Auditors require that the data remain unreadable if the physical disk is stolen, and that encryption keys never reside on the same disk as the ciphertext. Which approach BEST satisfies these requirements?
⚠ Common exam trap
The trap here is treating any form of encryption as sufficient, when the scenario specifically requires that key material not reside on the same disk as the encrypted data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable full disk encryption using a key stored in a hardware security module or external key manager.
The auditors require protection of data at rest plus separation of keys from ciphertext. Full disk encryption with keys held in an HSM or external key manager meets both conditions by ensuring a stolen disk yields only ciphertext and the key remains in a controlled, separate system. The other approaches either leave key material on the same disk or fail to provide equivalent protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use file-level encryption on individual tablespaces with passwords stored in a local script.
Why it's wrong here
Storing passwords in a local script on the same server again places key material with the ciphertext, defeating the purpose if the disk is stolen. File-level encryption also adds management overhead and does not inherently provide the key separation the auditors demand. A script is also a weak storage mechanism that can be read by anyone with file access.
- ✗
Apply column-level encryption using a symmetric key embedded in the application configuration file.
Why it's wrong here
Column-level encryption can protect specific fields, but embedding the key in an application configuration file on the same server violates the requirement that keys not reside with the ciphertext. If the disk is stolen, the configuration file likely goes with it, allowing decryption. This approach also complicates indexing and query performance without meeting the key separation requirement.
- ✗
Implement database transparent data encryption with keys managed by the database instance on the same volume.
Why it's wrong here
Transparent data encryption protects data files, but if the keys are stored on the same volume, a stolen disk could contain both ciphertext and key material. That fails the auditor's explicit condition. While TDE is valuable, it must be paired with external key management to meet the separation requirement described in the scenario.
- ✓
Enable full disk encryption using a key stored in a hardware security module or external key manager.
Why this is correct
Full disk encryption protects data at rest if the drive is removed, and storing the key in an HSM or external key manager ensures the key is not on the same disk as the ciphertext. This satisfies both auditor conditions: confidentiality of stolen media and separation of key material from encrypted data. It is the standard approach for data-at-rest protection on servers.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.