CompTIA DataSys+ (DS0-001)Database DeploymentHard

A development team has requested a new database instance for a highly sensitive application. The database will store personally identifiable information (PII) and must comply with strict regulatory requirements. As part of the installation and configuration, the database administrator needs to ensure that data at rest is encrypted. Which of the following is the most effective method to achieve this for the database files?

  1. AUsing SSL/TLS connections for all client-database communication.
  2. BEncrypting the operating system's swap space.
  3. CEnabling Transparent Data Encryption (TDE) at the database level.
  4. DImplementing column-level encryption for PII fields only.
Show answer & explanation

Correct answer: C. Enabling Transparent Data Encryption (TDE) at the database level.

Transparent Data Encryption (TDE) encrypts entire database files (datafiles, log files) at rest, typically at the OS or database block level, without requiring application changes. This is highly effective for sensitive data at rest and often meets regulatory compliance for protecting PII.

Why the other options are wrong

  • A. SSL/TLS encrypts data *in transit* (over the network), not data at rest (on disk).
  • B. Encrypting swap space is a good security practice but does not encrypt the primary database data files, which is the main target for PII at rest.
  • D. Column-level encryption is effective for specific fields but requires application changes and management of encryption keys per column, increasing complexity and potentially impacting query performance. It's not the most effective for *all database files*.

Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) is a technology that encrypts database files on disk without requiring changes to the application.

  • Encrypts data at rest (datafiles, log files, backups).
  • Encryption and decryption are handled automatically by the database engine.
  • Requires key management, often using a Hardware Security Module (HSM) or key vault.
  • Minimal impact on application code, making it 'transparent'.

Memory trick: TDE 'T'akes 'D'ata 'E'ncryption 'T'otally.

More Database Deployment questions