Certified Information Systems Security Professional (CISSP) — Question 472
The development team has been tasked with collecting data from biometric devices. The application will support a variety of collection data streams. During the testing phase, the team utilizes data from an old production database in a secure testing environment. What principle has the team taken into consideration?
Answer options
- A. Biometric data cannot be changed.
- B. The biometric devices are unknown.
- C. Biometric data must be protected from disclosure.
- D. Separate biometric data streams require increased security.
Correct answer: C
Explanation
The correct answer is C because it highlights the importance of protecting biometric data from unauthorized access or disclosure, especially during testing. Options A and B do not address the security aspect, and while option D mentions security, it does not directly relate to the principle of protecting existing data during the testing phase.