CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy
A financial institution is implementing a new database system to store sensitive customer financial records. Compliance regulations mandate that all sensitive data must be protected against unauthorized access, even if the underlying storage media is compromised. Which of the following security measures best addresses this requirement for data at rest?
- AEncrypting the entire database or specific sensitive columns within the database.
- BConfiguring regular database backups to an offsite location.
- CEnabling comprehensive logging and auditing of all database activities.
- DImplementing strong firewall rules to restrict network access to the database server.
Show answer & explanationAnswer & explanation
Correct answer: A. Encrypting the entire database or specific sensitive columns within the database.
Encrypting data at rest ensures that even if the storage media is stolen or compromised, the data remains unreadable without the decryption key. This directly addresses the requirement to protect sensitive data against unauthorized access on compromised storage.
Why the other options are wrong
- B. Backups provide data recovery but do not inherently protect data on compromised media from unauthorized viewing.
- C. Logging and auditing track access but do not prevent unauthorized access to data on compromised physical storage.
- D. Firewall rules protect against network-based attacks but not against physical compromise of storage media.
Encryption at Rest
The process of encrypting data when it is stored on a physical storage device, such as a hard drive or database.
- Protects data even if the storage media is stolen or accessed directly.
- Data is decrypted when accessed by authorized systems or users.
- Commonly applied to entire disks, filesystems, or specific database columns/tables.
Memory trick: Resting data needs a lock for peace.