CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy

A healthcare provider is upgrading its patient management system. The new system will allow authorized medical staff to access patient records from various clinics over a wide area network. Due to HIPAA regulations, all data exchanged between clinics and the central database must be protected from eavesdropping and tampering. Which of the following security measures is MOST appropriate to ensure data confidentiality and integrity during transmission?

  1. AApplying data masking techniques to sensitive patient identifiers.
  2. BUsing a Virtual Private Network (VPN) or Transport Layer Security (TLS) for all communication.
  3. CConfiguring robust database auditing to track all data access attempts.
  4. DImplementing row-level security within the database to restrict access.
Show answer & explanation

Correct answer: B. Using a Virtual Private Network (VPN) or Transport Layer Security (TLS) for all communication.

VPNs and TLS encrypt data in transit, ensuring confidentiality and integrity as it travels across networks. This directly addresses the requirement to protect data from eavesdropping and tampering during communication between clinics and the central database.

Why the other options are wrong

  • A. Data masking alters data for non-production environments but does not protect live data in transit.
  • C. Database auditing tracks actions but does not prevent eavesdropping or tampering of data during transmission.
  • D. Row-level security controls access within the database itself, not during network transmission.

Encryption in Transit

The process of encrypting data as it moves across a network from one point to another.

  • Protects data from eavesdropping and tampering during network communication.
  • Commonly implemented using protocols like TLS/SSL, VPNs, or IPsec.
  • Ensures confidentiality and integrity of data between client and server.

Memory trick: Traveling data needs a secure tunnel.

More Data and Database Security questions