CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy
A database administrator is configuring a new production database that will store sensitive customer financial information. The organization has a strict regulatory requirement to protect data even if the underlying storage media is compromised or stolen. Which of the following security measures would best address this specific requirement for data at rest?
- AEnabling database activity monitoring (DAM) for all read and write operations.
- BEncrypting the entire database files and backups using disk encryption.
- CImplementing strong user authentication with multi-factor authentication (MFA).
- DConfiguring network firewalls to restrict access to the database server.
Show answer & explanationAnswer & explanation
Correct answer: B. Encrypting the entire database files and backups using disk encryption.
Encrypting the entire database files and backups using disk encryption directly addresses the risk of data compromise if the physical storage media is stolen or accessed unauthorizedly. This ensures data is unreadable without the decryption key, fulfilling the requirement for data at rest protection.
Why the other options are wrong
- A. DAM monitors activities within the database but does not encrypt the data itself on the storage layer.
- C. Strong authentication protects access to the database, but not the data if the physical media is compromised.
- D. Firewalls protect network access, but do not secure data on stolen physical media.
Disk Encryption
Disk encryption is a technology that encrypts data on a hard drive or other storage device at the hardware or operating system level, protecting it from unauthorized access if the device is lost or stolen.
- Protects data at rest.
- Encrypts the entire volume or partition.
- Requires a key or passphrase to decrypt upon access.
Memory trick: Resting data needs a strong lock.