Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
An organization is implementing data encryption using symmetric ciphers and the Chief Information Officer (CIO) is concerned about the risk of using one key to protect all sensitive data, The security practitioner has been tasked with recommending a solution to address the CIO's concerns, Which of the following is the BEST approach to achieving the objective by encrypting all sensitive data?
Correct Answer: B
The best approach to achieving the objective of encrypting all sensitive data using symmetric ciphers, and addressing the CIO's concerns about the risk of using one key to protect all sensitive data, is to use a hierarchy of encryption keys. A hierarchy of encryption keys is a structure that involves using multiple levels or layers of encryption keys, such as master keys, key encryption keys, or data encryption keys, to encrypt and decrypt the data and the keys. A hierarchy of encryption keys can achieve the objective of encrypting all sensitive data using symmetric ciphers, as it can provide the same level of security and efficiency as symmetric encryption, which uses the same key for encryption and decryption. A hierarchy of encryption keys can also address the CIO's concerns about the risk of using one key to protect all sensitive data, as it can reduce the exposure and compromise of the keys, and increase the granularity and flexibility of the key management . References: [CISSP CBK, Fifth Edition, Chapter 3, page 248]; [100 CISSP Questions, Answers and Explanations, Question 17].