SSCP Systems and Application Security Practice Question
A security analyst is reviewing a mobile application that stores authentication tokens in a location accessible to other applications on the same device. The development team wants to remediate this finding for both Android and iOS. Which change BEST addresses the vulnerability?
⚠ Common exam trap
The trap here is accepting application-level encryption with a key embedded in the binary as equivalent to platform secure storage, when the key can be extracted by reverse engineering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store tokens in the platform-provided secure storage such as the Android Keystore and iOS Keychain.
The vulnerability is that tokens are readable by other applications. The platform secure storage mechanisms on Android and iOS are purpose-built to isolate secrets, and on capable hardware they can bind keys to the device's secure element. Hardcoded keys, permission-based files, and memory-only approaches either fail under realistic attacks or do not leverage the strongest available protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keep tokens in memory only and require reauthentication whenever the application restarts.
Why it's wrong here
Memory-only storage reduces persistence but harms usability and does not prevent memory scraping or debugging attacks on a compromised device. It also fails to use the secure storage facilities the platforms provide. While it limits exposure duration, it is not the best remediation for the stated vulnerability.
- ✗
Store tokens in a shared preferences file with file permissions restricted to the application's user ID.
Why it's wrong here
File permissions provide some isolation on a non-rooted device, but on rooted or jailbroken devices they can be bypassed, and backups or debugging interfaces may expose the file. This is weaker than platform secure storage and does not leverage hardware-backed protection. It leaves the tokens vulnerable in realistic threat scenarios.
- ✓
Store tokens in the platform-provided secure storage such as the Android Keystore and iOS Keychain.
Why this is correct
Platform secure storage is designed to isolate secrets from other applications and, on supported hardware, to protect them with hardware-backed keys. Moving tokens there prevents other apps from reading them and addresses the finding directly on both platforms. This is the recommended remediation for insecure local storage of credentials or tokens.
- ✗
Encrypt the tokens with a hardcoded symmetric key embedded in the application binary.
Why it's wrong here
A hardcoded key in the binary can be extracted through reverse engineering, so the encryption provides only obfuscation. An attacker with the application package can recover the key and decrypt the tokens. This does not fix the underlying exposure and may create a false sense of security for the development team.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.