CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium
A financial firm stores customer account records in cloud storage volumes. To protect this data in case the physical storage media is ever stolen or improperly decommissioned, the firm encrypts all data written to disk using AES-256. Which encryption state is being protected?
- AEncryption at rest
- BField-level tokenization
- CEncryption in transit
- DEncryption in use
Show answer & explanationAnswer & explanation
Correct answer: A. Encryption at rest
Encryption at rest protects data while it is stored on disk or other physical media, which addresses the risk of stolen or improperly disposed storage hardware. Encryption in transit protects data while it moves across networks, encryption in use protects data during processing in memory, and tokenization replaces sensitive values with non-sensitive tokens rather than encrypting the underlying data.
Why the other options are wrong
- B. Tokenization substitutes data with tokens rather than encrypting the original data on disk.
- C. In-transit encryption protects data moving over a network, not data sitting on storage media.
- D. In-use encryption protects data actively being processed in memory, a different scenario.
Encryption at Rest
The encryption of data while it is stored on disk, in databases, or other persistent storage media, protecting it from unauthorized access if storage is stolen or compromised.
- Protects against physical theft or improper disposal of storage media
- Common example: AES-256 disk/volume encryption
- Complements encryption in transit and encryption in use for full data protection
Memory trick: Rest, Transit, Use — lock the safe, the armored truck, and the workshop.