CompTIA Security+ (SY0-701)Security ArchitectureEasy

A hospital wants to protect patient records stored on file servers while the records are not actively being accessed or transmitted. Which control BEST protects the data in this state?

  1. AA stateful firewall at the network edge
  2. BFull-disk or file-level encryption
  3. CDigital signatures on outbound emails
  4. DTLS 1.3 for all client connections
Show answer & explanation

Correct answer: B. Full-disk or file-level encryption

Data that is stored and not moving is 'data at rest,' and the standard control for protecting it is encryption of the disk or files so that a stolen or improperly accessed drive is unreadable.

Why the other options are wrong

  • A. A firewall controls network traffic but does not protect stored data if accessed locally.
  • C. Digital signatures verify integrity of transmitted messages, not stored records.
  • D. TLS protects data in transit, not stored data.

Data at Rest

Data that is stored on a disk, database, or backup media and not currently being transmitted or processed.

  • Protected primarily with encryption (e.g., AES-256, BitLocker, TDE)
  • Contrasts with data in transit (TLS/IPsec) and data in use (memory encryption)
  • Loss of encryption keys can still expose data even if encrypted

Memory trick: 'Resting data needs a locked box' - encrypt it where it sits.

More Security Architecture questions