Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A cloud security engineer is tasked with ensuring that all sensitive data stored in their object storage service is protected against unauthorized viewing, even if an attacker gains access to the storage infrastructure itself. This protection must apply to data that is not actively being transferred. Which security best practice is being addressed?

  1. AMulti-factor authentication (MFA)
  2. BData in transit encryption
  3. CData at rest encryption
  4. DNetwork segmentation
Show answer & explanation

Correct answer: C. Data at rest encryption

Data at rest encryption protects data while it is stored on a persistent medium, rendering it unreadable without the correct decryption key, even if the storage infrastructure is compromised. This directly addresses protection for data 'not actively being transferred'.

Why the other options are wrong

  • A. MFA strengthens user authentication but doesn't encrypt the data itself on the storage device.
  • B. Data in transit encryption protects data as it moves across networks, not when it's stored.
  • D. Network segmentation isolates network traffic but does not encrypt the data itself once stored.

Data at Rest Encryption

The cryptographic protection of data that is stored on any persistent storage media, ensuring its confidentiality even if the storage medium or underlying infrastructure is compromised.

  • Applies to data on hard drives, SSDs, object storage, databases.
  • Renders data unreadable without the decryption key.
  • Crucial for compliance and data breach prevention.

Memory trick: Data 'at rest' should be 'resting' in an encrypted bed.

More Cloud Security questions