Security and Risk ManagementMedium

CISSP Practice Question: XYZ Corp needs to ensure compliance with data privacy regulations by encrypting…

Published July 21, 2026 · Free daily CISSP practice question
XYZ Corp needs to ensure compliance with data privacy regulations by encrypting sensitive data at rest on their servers. Which encryption method would BEST suit this requirement?
  1. A.AES-256
  2. B.SHA-256
  3. C.RSA-2048
  4. D.MD5
Correct answer: A. AES-256

Correct Answer: A. AES-256

Explanation (CISSP Manager Logic):

AES-256 is the industry standard for symmetric bulk data encryption, providing the optimal balance of performance and high-strength security for data at rest. It satisfies regulatory requirements for protecting sensitive information while ensuring operational efficiency.

By implementing this solution, you:

  • Ensure high-speed processing of large data volumes with minimal latency.
  • Meet international compliance standards for data privacy and protection.
  • Maintain confidentiality through a robust, globally recognized algorithm.

While the other options are relevant, they fall short because:

  • B: SHA-256 is a hashing algorithm used for integrity, not for encrypting or recovering data.
  • C: RSA-2048 is an asymmetric algorithm that is too computationally expensive for bulk data encryption.
  • D: MD5 is a legacy hashing algorithm that is cryptographically broken and provides no confidentiality.

Think like a manager:

Prioritize efficiency and proven standards when selecting controls. Use symmetric encryption for bulk data at rest to balance regulatory compliance with system performance.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions Next question →