CompTIA Security+ (SY0-701)Security ArchitectureEasy
A company's compliance officer requires that sensitive financial data remain encrypted even while it is being processed in memory by a cloud application, protecting it from a compromised hypervisor or malicious cloud administrator. Which concept addresses this requirement?
- AData masking
- BData in use protection (confidential computing)
- CData in transit encryption
- DData at rest encryption
Show answer & explanationAnswer & explanation
Correct answer: B. Data in use protection (confidential computing)
Data in use protection, often implemented through confidential computing and hardware-based trusted execution environments (enclaves), encrypts data while it is actively being processed in memory, preventing exposure even to the underlying host or hypervisor.
Why the other options are wrong
- A. Masking obscures values for display, not full processing encryption.
- C. Protects data moving across a network, not data in memory.
- D. Protects stored data, not data actively being processed.
Data in Use
Protection applied to data while it is actively being processed in CPU/memory, typically via hardware-based trusted execution environments.
- Complements data-at-rest and data-in-transit protections
- Uses secure enclaves (e.g., trusted execution environments)
- Protects against compromised hosts, hypervisors, or insiders
Memory trick: Rest, Transit, Use — three states, three shields.