CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A large enterprise is migrating its on-premises data warehouse to a cloud-native platform. The data warehouse contains petabytes of sensitive customer transaction data, and the migration requires a phased approach. The security architect needs to design a solution that ensures data privacy and compliance with various regulations during the migration process, especially when data is transferred between the on-premises and cloud environments, and while it resides in temporary cloud storage before final integration. Which data security control is paramount for protecting this sensitive data during its journey and temporary residency in the cloud?

  1. AConfiguring network segmentation within the cloud environment.
  2. BUtilizing Data Loss Prevention (DLP) solutions on egress points.
  3. CImplementing strong firewall rules at the cloud perimeter.
  4. DApplying end-to-end encryption for data in transit and at rest.
Show answer & explanation

Correct answer: D. Applying end-to-end encryption for data in transit and at rest.

End-to-end encryption for data in transit and at rest is paramount for protecting sensitive data during migration to the cloud. This ensures that even if data is intercepted during transfer or accessed from temporary storage, it remains unreadable and protected, directly addressing privacy and compliance requirements.

Why the other options are wrong

  • A. Network segmentation helps limit the blast radius of a breach but does not inherently protect the confidentiality of the data itself if an unauthorized entity gains access within a segment.
  • B. DLP solutions prevent data exfiltration but primarily focus on data leaving the control of the organization, not on protecting data during its legitimate transfer and storage within the migration process.
  • C. Firewall rules control network traffic but do not protect data if it's accessed by an authorized but malicious actor, or if the perimeter is breached.

End-to-End Data Encryption

The practice of encrypting data at its origin and decrypting it only at its final destination, ensuring it remains protected throughout its entire lifecycle, including in transit and at rest.

  • Protects data confidentiality from source to destination.
  • Crucial for sensitive data, especially during cloud migrations.
  • Combines encryption for data in transit (e.g., TLS) and at rest (e.g., disk encryption).

Memory trick: Moving sensitive data is like shipping valuables; you need a 'locked, armored truck' and a 'secure vault' at the destination.

More Security Architecture questions