Q: 6
A financial services firm has detected a security vulnerability in a cloud-based application provided by an external vendor. To manage communication with the vendor effectively, which of the following actions should the Incident Response Team take first?
Options
Discussion
C , asymmetric is more secure and IPSec can cover in-transit, but not sure if that's the HIPAA trap.
C isn’t right here, D matches real HIPAA compliance setups. Asymmetric at rest (C) is rare and usually a distractor.
C tbh, asymmetric encryption feels like the strongest pick for data at rest and IPSec covers transit. That's what I remember from some official guide examples. Anyone review this in labs or practice tests?
D , saw a super similar question in a practice set and it was all about showing compliance. SSL/TLS + customer-managed keys checks both HIPAA and encryption needs.
I picked C because asymmetric encryption seems stronger for key management, and IPSec does encrypt in transit. But now I’m realizing customer-managed keys in D probably match HIPAA compliance better. Anyone else thought C looked close?
Its D for sure, official study guides and cloud provider docs both cover customer-managed keys and SSL/TLS as HIPAA best practices.
D imo, C is tempting but HIPAA compliance needs you to control the keys, which D covers with customer-managed keys. A and B miss key management and proper protocols. Pretty sure about this, calling out C as a common distractor.
C/D? Pretty close since both deal with strong encryption, but HIPAA usually expects server-side encryption with CMK (like D) for proper key control. Asymmetric at rest (C) isn't that common in the real world so I'm leaning D, but not 100%.
I don't think C is the best fit here. D lines up better with common compliance practice-SSL/TLS for in transit and customer-managed keys for server-side at rest meet HIPAA expectations. C uses asymmetric at rest, but that's not typical. If I'm off, let me know.
Its D, static keys in app code (B) is a common trap for compliance questions.
Be respectful. No spam.