CompTIA Server+ (SK0-005)Security and Disaster RecoveryMedium

A server administrator is deploying a new web application that will handle sensitive customer payment information. The company's compliance regulations require that all data at rest on the server's storage must be encrypted. Which encryption method should be implemented to protect the entire disk volume where the application and its data reside?

  1. AFile-level encryption for specific data files.
  2. BDatabase encryption for the payment database.
  3. CApplication-level encryption for payment transactions.
  4. DFull Disk Encryption (FDE) at the operating system level.
Show answer & explanation

Correct answer: D. Full Disk Encryption (FDE) at the operating system level.

Full Disk Encryption (FDE) encrypts the entire disk volume, including the operating system, applications, and data. This ensures that all data at rest is protected, meeting the requirement for encrypting all data on the server's storage.

Why the other options are wrong

  • A. File-level encryption only protects specific files, leaving other data on the disk vulnerable.
  • B. Database encryption protects only the data within the database, not the entire disk or other application components.
  • C. Application-level encryption protects data within the application context, typically before it's written to disk or during transmission, but not necessarily all data at rest on the disk.

Full Disk Encryption (FDE)

A security method that encrypts all data on a hard drive or storage device, including the operating system and user files.

  • Protects data at rest.
  • Requires authentication at boot.
  • Can be hardware or software-based.

Memory trick: Data at rest, needs a 'full' lock.

More Security and Disaster Recovery questions