CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a data security strategy for a new cloud application that processes highly sensitive personal identifiable information (PII). The requirement is to ensure that even if the application's database is compromised, the PII remains unreadable and unusable to an attacker, while still allowing the application to perform searches and analytics on the data without full decryption. Which data security technique is BEST suited for this specific requirement?

  1. AHomomorphic Encryption.
  2. BColumn-level Encryption.
  3. CTokenization.
  4. DFull Disk Encryption (FDE).
Show answer & explanation

Correct answer: A. Homomorphic Encryption.

Homomorphic encryption allows computations (like searches or analytics) to be performed directly on encrypted data without first decrypting it. This uniquely addresses the requirement to keep PII unreadable in a compromised database while still enabling processing, making it superior to other methods that require decryption for operations or only provide obfuscation.

Why the other options are wrong

  • B. Column-level encryption encrypts specific columns in a database. While it protects the data at rest, performing operations like searches or analytics on the encrypted column usually requires decryption, exposing the data at some point, or it would only work for exact matches on encrypted values, not complex analytics on the underlying data.
  • C. Tokenization replaces sensitive data with non-sensitive tokens, protecting the original PII. However, complex searches or analytics on the *original* data values (not just the tokens) typically require access to the original data, which would mean decryption or de-tokenization.
  • D. FDE encrypts the entire storage device, protecting against physical theft, but once the system is running and the disk is mounted, data can be accessed by the application and thus by a compromised application.

Homomorphic Encryption

Homomorphic encryption is a form of encryption that allows computations to be performed on encrypted data without decrypting it first. The result of the computation is also in an encrypted form and, when decrypted, matches the result of the operations as if they had been performed on the plaintext.

  • Enables computation on encrypted data.
  • Maintains data confidentiality during processing.
  • Still largely computationally intensive and complex for widespread use, but ideal for specific scenarios.
  • Supports various operations (addition, multiplication, etc.).

Memory trick: Homomorphic Encryption is like doing 'math with locked boxes' – you get the right answer without ever opening them.

More Security Architecture questions