CompTIA DataSys+ (DS0-001)Data and Database SecurityHard

A government agency is migrating a legacy database containing classified information to a new platform. Strict regulations mandate that all data, even when residing in backup files or temporary storage, must be completely unintelligible to unauthorized individuals. The chosen encryption method must also be robust enough to withstand future cryptographic advancements. Which type of encryption is MOST suitable for ensuring the long-term confidentiality of this highly sensitive data at rest?

  1. ASymmetric encryption with a 128-bit key
  2. BQuantum-resistant encryption algorithms
  3. CAsymmetric encryption with a 2048-bit key
  4. DFormat-preserving encryption
Show answer & explanation

Correct answer: B. Quantum-resistant encryption algorithms

Given the requirement for long-term confidentiality against 'future cryptographic advancements' and 'classified information', quantum-resistant encryption algorithms (also known as post-quantum cryptography) are the most suitable choice. These algorithms are designed to be secure against attacks by future quantum computers, which could potentially break current symmetric and asymmetric encryption standards.

Why the other options are wrong

  • A. 128-bit symmetric keys are currently strong but might be vulnerable to future quantum attacks, especially for 'long-term' protection of 'classified' data.
  • C. 2048-bit asymmetric keys are strong against classical computers but also susceptible to quantum algorithms like Shor's algorithm.
  • D. Format-preserving encryption maintains data format but doesn't inherently guarantee resistance to future quantum attacks or provide the strongest level of confidentiality for classified data.

Quantum-Resistant Encryption

Cryptographic algorithms designed to be secure against attacks by future quantum computers, ensuring long-term confidentiality and integrity.

  • Also known as Post-Quantum Cryptography (PQC).
  • Aims to replace current algorithms (RSA, ECC, AES) vulnerable to quantum attacks.
  • Crucial for protecting data with long-term security requirements.

Memory trick: Long-term secrets need a lock that future tech can't pick.

More Data and Database Security questions