nerdexam
(ISC)2

CISSP · Question #734

An organization is designing a large enterprise-wide document repository system. They plan to have several different classification level areas with increasing levels of controls. The BEST way to ensu

The correct answer is A. encrypt the contents of the repository and document any exceptions to that requirement.. The best way to ensure document confidentiality in the repository is to encrypt the contents of the repository and document any exceptions to that requirement. Encryption is the process of transforming the information into an unreadable form using a secret key or algorithm. Encry

Submitted by brentm· Mar 5, 2026Security Architecture and Engineering

Question

An organization is designing a large enterprise-wide document repository system. They plan to have several different classification level areas with increasing levels of controls. The BEST way to ensure document confidentiality in the repository is to

Options

  • Aencrypt the contents of the repository and document any exceptions to that requirement.
  • Butilize Intrusion Detection System (IDS) set drop connections if too many requests for documents
  • Ckeep individuals with access to high security areas from saving those documents into lower
  • Drequire individuals with access to the system to sign Non-Disclosure Agreements (NDA).

How the community answered

(30 responses)
  • A
    80% (24)
  • B
    3% (1)
  • C
    10% (3)
  • D
    7% (2)

Explanation

The best way to ensure document confidentiality in the repository is to encrypt the contents of the repository and document any exceptions to that requirement. Encryption is the process of transforming the information into an unreadable form using a secret key or algorithm. Encryption protects the confidentiality of the information by preventing unauthorized access or disclosure, even if the repository is compromised or breached. Encryption also provides integrity and authenticity of the information by ensuring that it has not been modified or tampered with. Documenting any exceptions to the encryption requirement is also important to justify the reasons and risks for not encrypting certain information, and to apply alternative controls if needed.

Topics

#data confidentiality#encryption#data at rest#document repository security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice