CompTIA DataSys+ (DS0-001)Database Management and MaintenanceHard

A database administrator needs to ensure that sensitive customer data, such as credit card numbers, is not visible in plain text within the database, even to users with direct database access. Which database security feature is BEST suited for this requirement?

  1. AData masking.
  2. BRow-level security (RLS).
  3. CColumn-level encryption.
  4. DTransparent Data Encryption (TDE).
Show answer & explanation

Correct answer: C. Column-level encryption.

Column-level encryption directly encrypts specific sensitive columns within a table. This satisfies the requirement that the data is not visible in plain text, even to users with direct database access, unless they have the appropriate decryption keys or permissions. TDE encrypts the entire database at rest, but data is decrypted in memory and available in plain text to authorized users. Data masking obscures data for non-production environments or specific users, but often doesn't involve actual encryption of the production data at rest.

Why the other options are wrong

  • A. Data masking replaces sensitive data with non-sensitive but realistic data, typically for non-production environments or specific roles. It's about obscuring data, not necessarily encrypting the actual sensitive data in the production database for all authorized users with direct access.
  • B. Row-level security restricts which rows a user can see, not whether the data within a visible row is encrypted or masked.
  • D. Transparent Data Encryption (TDE) encrypts the entire database files at rest. However, once the database is online and a user is authenticated, the data is decrypted in memory and presented in plain text to authorized users, which doesn't meet the requirement of not being visible in plain text to 'users with direct database access'.

Column-Level Encryption

The practice of encrypting specific, sensitive columns within a database table, rather than the entire database or table.

  • Provides granular protection for highly sensitive data.
  • Data remains encrypted on disk and in memory until explicitly decrypted by authorized processes/users.
  • Requires key management and can impact query performance on encrypted columns.

Memory trick: TDE for files, Column for fields, RLS for rows, Masking for fakes.

More Database Management and Maintenance questions