CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy
A financial institution is implementing a new database system to store sensitive customer financial data. Regulatory compliance dictates that this data must be protected even if the underlying storage media is compromised. Which security measure is MOST appropriate to ensure data confidentiality in this scenario?
- ARole-based access control (RBAC)
- BDatabase activity monitoring
- CTransparent Data Encryption (TDE)
- DSecure Sockets Layer (SSL) for connections
Show answer & explanationAnswer & explanation
Correct answer: C. Transparent Data Encryption (TDE)
Transparent Data Encryption (TDE) encrypts the entire database or specific tablespaces at rest, meaning the data is protected even if the physical storage is stolen or accessed directly. This directly addresses the requirement for data confidentiality if the storage media is compromised.
Why the other options are wrong
- A. RBAC controls who can access data but does not encrypt the data itself on storage.
- B. Database activity monitoring logs database events but does not encrypt data at rest.
- D. SSL encrypts data in transit, not data at rest on storage media.
Transparent Data Encryption (TDE)
A technology used to encrypt an entire database's data files at rest, protecting data on storage media without requiring application changes.
- Encrypts data files, log files, and backups.
- Protects data from unauthorized access to storage media.
- Usually implemented at the database engine level.
Memory trick: Confidentiality demands a lock on the data storage.