Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A security engineer is evaluating different methods to protect sensitive data stored in a cloud object storage service. Which security measure, when applied to the stored data itself, provides protection even if the storage infrastructure is compromised?

  1. AVirtual Private Cloud (VPC) segmentation
  2. BData encryption at rest
  3. CSecurity groups
  4. DNetwork access control lists (NACLs)
Show answer & explanation

Correct answer: B. Data encryption at rest

Data encryption at rest renders the data unreadable to unauthorized parties, even if they gain access to the underlying storage infrastructure. NACLs, VPCs, and security groups protect network access, not the data itself if storage is directly compromised.

Why the other options are wrong

  • A. VPC segmentation isolates network environments, but doesn't encrypt data within a compromised storage service.
  • C. Security groups act as virtual firewalls for instances, controlling network access, not directly protecting data within compromised storage.
  • D. NACLs control network traffic to and from subnets, not the data's integrity or confidentiality if the storage itself is breached.

Data Encryption at Rest

The process of encoding data while it is stored on a persistent storage medium, protecting it from unauthorized access even if the storage infrastructure is compromised.

  • Protects data confidentiality on disk or in storage.
  • Uses cryptographic algorithms to scramble data.
  • Requires a key for decryption and access.

Memory trick: Encrypt data at rest, so even if it rests in the wrong hands, it's still secret.

More Cloud Security questions