Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A company is implementing a new data handling policy to ensure that sensitive customer information remains confidential even if the storage server is compromised. Which security measure, when applied to the data at rest, would best achieve this goal?

  1. AIntrusion detection systems (IDS)
  2. BData encryption
  3. CNetwork segmentation
  4. DRegular data backups
Show answer & explanation

Correct answer: B. Data encryption

Data encryption at rest ensures that even if an unauthorized party gains access to the storage server and the data files, they will not be able to read the sensitive information without the decryption key. This directly addresses the confidentiality goal in a compromise scenario.

Why the other options are wrong

  • A. Intrusion detection systems alert to attacks but do not protect data confidentiality once the data has been accessed or exfiltrated.
  • C. Network segmentation helps prevent unauthorized access to the server but doesn't protect data if the server itself is compromised.
  • D. Regular data backups help with availability and recovery, not confidentiality in case of compromise.

Data Encryption

Data encryption is the process of converting information into a code to prevent unauthorized access. It scrambles data into an unreadable format, making it secure during storage (at rest) and transmission (in transit).

  • Protects confidentiality.
  • Requires a key for decryption.
  • Applied to data at rest or in transit.

Memory trick: Encryption is like putting your secret diary in a locked box, even if someone finds the box, they can't read it.

More Security Principles questions