CompTIA Security+ (SY0-701)Security ArchitectureEasy
A hospital wants to protect patient records stored on file servers while the records are not actively being accessed or transmitted. Which control BEST protects the data in this state?
- AA stateful firewall at the network edge
- BFull-disk or file-level encryption
- CDigital signatures on outbound emails
- DTLS 1.3 for all client connections
Show answer & explanationAnswer & explanation
Correct answer: B. Full-disk or file-level encryption
Data that is stored and not moving is 'data at rest,' and the standard control for protecting it is encryption of the disk or files so that a stolen or improperly accessed drive is unreadable.
Why the other options are wrong
- A. A firewall controls network traffic but does not protect stored data if accessed locally.
- C. Digital signatures verify integrity of transmitted messages, not stored records.
- D. TLS protects data in transit, not stored data.
Data at Rest
Data that is stored on a disk, database, or backup media and not currently being transmitted or processed.
- Protected primarily with encryption (e.g., AES-256, BitLocker, TDE)
- Contrasts with data in transit (TLS/IPsec) and data in use (memory encryption)
- Loss of encryption keys can still expose data even if encrypted
Memory trick: 'Resting data needs a locked box' - encrypt it where it sits.