Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard

A cloud security architect is designing a highly secure environment for a financial services application that processes sensitive customer data. The application will leverage multiple cloud services, including compute, storage, and databases. To ensure that all data, regardless of where it resides within the cloud provider's infrastructure, is unreadable without proper authorization, what overarching security principle should be rigorously applied?

  1. AContinuous monitoring
  2. BNetwork segmentation
  3. CData encryption (at rest and in transit)
  4. DPrinciple of least privilege
Show answer & explanation

Correct answer: C. Data encryption (at rest and in transit)

To ensure that all data is unreadable without proper authorization, the overarching principle is data encryption, both when it's stored (at rest) and when it's moving between services (in transit). This directly addresses the 'unreadable without proper authorization' requirement across all data states.

Why the other options are wrong

  • A. Continuous monitoring detects issues but does not prevent data from being read if accessed without encryption.
  • B. Network segmentation separates networks, but doesn't make data unreadable if an unauthorized party gains access within a segment.
  • D. Least privilege controls who can access data, but doesn't make the data itself unreadable if accessed.

Ubiquitous Data Encryption

The comprehensive application of encryption to all sensitive data, both when it is stored (at rest) and when it is being transmitted (in transit), across all cloud services.

  • Protects data confidentiality
  • Applies to data at rest (storage) and in transit (network)
  • Fundamental for sensitive data in cloud environments

Memory trick: Encrypt everything, everywhere, always.

More Cloud Security questions