Security Architecture and Engineering Question #128

A bank is integrating a third-party analytics vendor. To minimize the risk of data leaks during regular data exchanges, which measure should be prioritized?

A. Conducting a third-party risk assessment before integration.
B. Implementing data tokenization techniques on sensitive data prior to exchange.
C. Establishing a symmetric-key dedicated VPN for secure data transfers.
D. Requiring the third-party vendor to maintain SOC 2 certification.
Domain Concept: Security Architecture and Engineering

This scenario evaluates management-level decision making in Security Architecture and Engineering. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top