CompTIA SecurityX (CAS-005)Security OperationsHard

A security architect is designing a new cloud-based application and needs to ensure that sensitive data handled by the application is protected both in transit and at rest. The application will interact with several microservices and store data in a NoSQL database. Which combination of cryptographic controls should the architect prioritize to meet these requirements?

  1. AHTTPS for data in transit and hardware security modules (HSMs) for key management.
  2. BTLS for data in transit and client-side encryption with strong access controls for data at rest.
  3. CVPN for data in transit and full disk encryption for data at rest.
  4. DSSH for data in transit and symmetric encryption for data at rest.
Show answer & explanation

Correct answer: B. TLS for data in transit and client-side encryption with strong access controls for data at rest.

TLS (Transport Layer Security) is the standard for securing data in transit over networks, commonly used by microservices. Client-side encryption ensures that data is encrypted before it leaves the application and is stored in the NoSQL database, offering stronger protection than database-managed encryption, especially when combined with strong access controls.

Why the other options are wrong

  • A. HTTPS is a protocol using TLS, so TLS is more general. HSMs are critical for key management, but this option omits the actual encryption of data at rest, which is the primary concern for sensitive data in a NoSQL database, making it incomplete.
  • C. VPNs are for network-level tunnels, not granular application data transit. Full disk encryption protects the entire disk, but for sensitive data within a database, more granular control like client-side encryption is superior.
  • D. SSH is typically for secure shell access, not general application-to-application data transit. Symmetric encryption is part of data at rest, but client-side encryption is more robust for sensitive data in a NoSQL database.

Client-Side Encryption

The process of encrypting data on the user's or application's device before it is transmitted to a cloud service or stored in a database, ensuring that the cloud provider never has access to unencrypted sensitive data.

  • User/application controls the encryption keys.
  • Protects data even if the cloud provider is compromised.
  • Can make search and indexing more complex.

Memory trick: Cloud data needs two shields: one for travel, one for rest.

More Security Operations questions