CompTIA Security+ (SY0-701)Security ArchitectureEasy

A company's compliance officer requires that sensitive financial data remain encrypted even while it is being processed in memory by a cloud application, protecting it from a compromised hypervisor or malicious cloud administrator. Which concept addresses this requirement?

  1. AData masking
  2. BData in use protection (confidential computing)
  3. CData in transit encryption
  4. DData at rest encryption
Show answer & explanation

Correct answer: B. Data in use protection (confidential computing)

Data in use protection, often implemented through confidential computing and hardware-based trusted execution environments (enclaves), encrypts data while it is actively being processed in memory, preventing exposure even to the underlying host or hypervisor.

Why the other options are wrong

  • A. Masking obscures values for display, not full processing encryption.
  • C. Protects data moving across a network, not data in memory.
  • D. Protects stored data, not data actively being processed.

Data in Use

Protection applied to data while it is actively being processed in CPU/memory, typically via hardware-based trusted execution environments.

  • Complements data-at-rest and data-in-transit protections
  • Uses secure enclaves (e.g., trusted execution environments)
  • Protects against compromised hosts, hypervisors, or insiders

Memory trick: Rest, Transit, Use — three states, three shields.

More Security Architecture questions