CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A healthcare provider is required by HIPAA to ensure the confidentiality and integrity of Protected Health Information (PHI) stored in their databases. They want to implement a solution that encrypts the entire database, including tables, indexes, and logs, without requiring application-level changes. Which encryption method is suitable for this requirement?

  1. AColumn-level encryption
  2. BApplication-level encryption
  3. CField-level encryption
  4. DTransparent Data Encryption (TDE)
Show answer & explanation

Correct answer: D. Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) encrypts entire database files at rest, including data files, log files, and backups, without requiring any changes to application code. It's 'transparent' because applications interact with the data as if it were unencrypted, fulfilling the requirement for whole-database encryption without application modifications.

Why the other options are wrong

  • A. Column-level encryption requires specific columns to be encrypted, often needing application changes.
  • B. Application-level encryption means the application itself encrypts/decrypts data, requiring significant code changes.
  • C. Field-level encryption is similar to column-level, focusing on individual data fields, and typically needs application awareness.

Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) is a technology that encrypts and decrypts database data files, log files, and backups in real-time at the I/O layer, without requiring changes to existing applications. It protects data at rest.

  • Encrypts entire database files.
  • Transparent to applications.
  • Protects data at rest (storage media).
  • Encrypts data, log, and backup files.

Memory trick: TDE hides the whole database.

More Data and Database Security questions