Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 176 discussion

Actual exam question from ISC's CISSP
Question #: 176
Topic #: 1
[All CISSP Questions]

The development team has been tasked with collecting data from biometric devices. The application will support a variety of collection data streams. During the testing phase, the team utilizes data from an old production database in a secure testing environment. What principle has the team taken into consideration?

  • A. Biometric data cannot be changed.
  • B. The biometric devices are unknown.
  • C. Biometric data must be protected from disclosure.
  • D. Separate biometric data streams require increased security.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Li_Rong_Han
Highly Voted 2 years, 2 months ago
The question says: "the team utilizes data from an old production database in a secure testing environment." If you are going to use REAL data from a production database in a testing/staging environment, you should consider the confidentiality of those data. C. Biometric data must be protected from disclosure.
upvoted 11 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
pete79
Most Recent 9 months, 3 weeks ago
Selected Answer: A
They were tasked to collect biometric data, but they ended reuse existing DB, hence it implies that biometric data cannot be changed, therefore old DB is good as it contains valid data.
upvoted 1 times
...
Socca
1 year, 1 month ago
A is correct Biomitric data can't be changed. Biomitric data can be stored for 10 years by government for relative use
upvoted 2 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: C
The principle taken into consideration by the team from the point of view of a CISSP is: C. Biometric data must be protected from disclosure. By utilizing data from an old production database in a secure testing environment, the team is ensuring that the biometric data is kept confidential and not disclosed to unauthorized individuals or parties. This is an important aspect of biometric data security, as such data is highly sensitive and can be used for identity theft or other malicious purposes if it falls into the wrong hands.
upvoted 1 times
...
Nicola_2_Reg
1 year, 2 months ago
Biometric datas are setup to be true all the time of your life... Therefore even if from an old production, the information remains correct/exact. Non disclosure preveals !
upvoted 1 times
...
HughJassole
1 year, 5 months ago
A and C are both correct: "You can change passwords, but you can’t change your biometric details. If your biometric data is stolen or lost, it could be permanently compromised." "if biometric data is exposed, the risk of identity theft and fraud rises." https://www.avast.com/c-what-is-biometric-data#:~:text=A%20biometric%20is%20only%20as,t%20change%20your%20biometric%20details. The question asks for the principle used when the team utilized a secure environment. Seems like they are guiding towards C.
upvoted 2 times
...
pete79
1 year, 6 months ago
Selected Answer: A
They wrongly assumed that Biometric data cannot be change, hence ended up using prod DB.
upvoted 2 times
...
Rollingalx
1 year, 8 months ago
I go with C Option A is not applicable in this scenario as it refers to the immutability of biometric data, which means that once biometric data is collected, it cannot be changed.
upvoted 1 times
...
sausageman
1 year, 8 months ago
A seems correct. C doesn't make any sense in this context
upvoted 3 times
...
oudmaster
1 year, 11 months ago
Selected Answer: C
May I know whom decide the correct answers of these questions? Is it based on the passing rate of CISSP exam?
upvoted 4 times
omarb79
1 year, 7 months ago
Are these questions from this website are coming the real CISSP exam ?
upvoted 2 times
...
...
sphenixfire
1 year, 11 months ago
Selected Answer: C
"Any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information. ...The key is that organizations have a responsibility to protect PII. This includes PII related to employees and customers. Many laws require organizations to notify individuals if a data breach results in a compromise of PII." CISSP 9th ed. off. study guide
upvoted 2 times
...
IXone
2 years ago
I think the answer a is correct
upvoted 3 times
...
projtfer
2 years, 1 month ago
Selected Answer: C
It does not ask what is the purpose of collecting biometric data, there for A is wrong. C is right because the question is about why the biometric data is tested in a secure old prod environment.
upvoted 3 times
...
Cww1
2 years, 2 months ago
hate the question, i think its A though
upvoted 2 times
...
stickerbush1970
2 years, 2 months ago
reread the question, C doesn't even make sense in this aspect.
upvoted 2 times
...
DERCHEF2009
2 years, 2 months ago
Selected Answer: C
I think its C
upvoted 4 times
DERCHEF2009
2 years, 2 months ago
Jea its A
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...