CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is tasked with ensuring the confidentiality and integrity of data at rest on user endpoints (laptops, mobile devices) for a highly mobile workforce. The solution must ensure that even if a device is lost or stolen, sensitive data remains unreadable. Which encryption strategy is most effective for this scenario?
- ADatabase encryption at the application layer
- BServer-side encryption
- CClient-side encryption
- DNetwork-level encryption (e.g., VPN)
Show answer & explanationAnswer & explanation
Correct answer: C. Client-side encryption
Client-side encryption ensures that data is encrypted on the user's device before it is stored, meaning that if the device is compromised, the data remains unreadable without the client's encryption key. This directly addresses data at rest on endpoints.
Why the other options are wrong
- A. Database encryption protects data within a database, typically on a server, not on individual user endpoints.
- B. Server-side encryption protects data at rest on servers, not on client endpoints.
- D. Network-level encryption (VPN) protects data in transit, not data at rest on the endpoint.
Client-Side Encryption
The process of encrypting data on the user's device (client) before it is transmitted to a server or stored locally, ensuring that the data remains encrypted and unreadable to anyone without the client's decryption key.
- Protects data at rest on endpoints.
- Ensures data confidentiality even if the server/storage is compromised.
- User often holds the encryption key, increasing privacy.
Memory trick: Client-Side Encryption: 'Cloaks Local Information' on your device.