Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 13
Melissa is the new IT Security Manager of a global corporation. Her predecessor started implementing the ISO/IEC 7498-1 (OSI) model, but she needs to continue this process, making sure that she maintains the highest level of security possible. Based on her knowledge of the ISO/IEC 7498-1 model, which of the following steps should she prioritize in order to increase security?
- A Applying end-to-end encryption at the application layer.
- B Defining interfaces at the presentation layer.
- C Developing a protocol for addressing at the network layer.
- D Ensuring data integrity at the transport layer.
Reveal correct answer
Correct answer: A
Explanation
The correct answer: Applying end-to-end encryption at the application layer: The application layer, being the topmost layer of the OSI model, provides a set of interfaces for applications to obtain access to networked services. Applying end-to-end encryption at this layer ensures that data remains confidential from the point of origin to its destination, safeguarding against eavesdropping and potential data manipulation. The incorrect answers: Ensuring data integrity at the transport layer: While ensuring data integrity at the transport layer is essential, this layer mainly provides reliable data transfer services between two network hosts. Data integrity can be ensured here, but confidentiality might not be fully addressed. Developing a protocol for addressing at the network layer: The network layer is primarily responsible for routing, addressing, and forwarding data packets. Developing an addressing protocol is more about ensuring efficient and reliable data transfer than about heightening security. Defining interfaces at the presentation layer: The presentation layer deals with data translation, encryption, and compression. While defining clear interfaces here is essential for interoperability, it doesn't directly increase security to the same extent as applying end-to-end encryption at the application layer.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
