Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A client is developing a new application that will process highly sensitive personal identifiable information (PII). They want to ensure that if the data is ever exfiltrated or accessed by unauthorized individuals, it remains unintelligible and unusable. Which security control directly addresses this requirement?
- AAccess Control List (ACL)
- BFirewall
- CEncryption
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: C. Encryption
Encryption transforms data into an unreadable format, ensuring that even if unauthorized individuals gain access, the data remains unintelligible and unusable without the proper decryption key. This directly addresses the requirement for data to be unusable if exfiltrated.
Why the other options are wrong
- A. ACLs control who can access resources, but don't protect data if it bypasses these controls (e.g., exfiltration).
- B. A Firewall controls network traffic, preventing unauthorized access but not making exfiltrated data unintelligible.
- D. An IDS detects malicious activity but doesn't protect data once it's exfiltrated.
Encryption
The process of converting information or data into a code to prevent unauthorized access, making it unreadable without the correct key.
- Protects data at rest and in transit.
- Essential for confidentiality.
- Uses algorithms and keys to scramble/unscramble data.
Memory trick: Encryption: 'Scrambles the message so only the right key can read it.'