CompTIA DataSys+ (DS0-001)Database Management and MaintenanceMedium

A data engineer is designing a new database for a financial application that will store sensitive customer transaction data. They need to ensure that specific columns, such as `credit_card_number` and `account_balance`, are protected such that only authorized applications or users can decrypt and view their actual values, even if the underlying database files are compromised. Which security mechanism is BEST suited for this requirement?

  1. AColumn-Level Encryption (CLE).
  2. BDatabase link encryption.
  3. CFirewall rules on the database server.
  4. DTransparent Data Encryption (TDE).
Show answer & explanation

Correct answer: A. Column-Level Encryption (CLE).

Column-Level Encryption (CLE) is designed to encrypt specific columns within a table, allowing granular control over which data is protected and requiring application-level decryption for access, fulfilling the requirement for selective data protection.

Why the other options are wrong

  • B. Database link encryption protects data in transit between databases, not data at rest within specific columns.
  • C. Firewall rules protect against unauthorized network access but do not encrypt data within the database files themselves.
  • D. TDE encrypts the entire database at rest but does not provide granular control over specific columns, and data is decrypted in memory for any authorized user.

Column-Level Encryption (CLE)

A database security feature that encrypts specific columns within a table, providing granular protection for sensitive data. Decryption typically occurs at the application layer or by authorized database users.

  • Encrypts only designated columns, not the entire database.
  • Offers fine-grained control over sensitive data.
  • Requires application or user-level decryption keys for access.

Memory trick: Columns have their own locks, not the whole building.

More Database Management and Maintenance questions