Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy
A bank is implementing a new customer portal that will handle sensitive financial information. They want to ensure that if the underlying infrastructure is compromised, the sensitive data itself remains unreadable and unusable to unauthorized parties. Which security control would primarily achieve this goal?
- AEncryption
- BAccess Control Lists (ACLs)
- CNetwork Segmentation
- DIntrusion Detection Systems (IDS)
Show answer & explanationAnswer & explanation
Correct answer: A. Encryption
Encryption transforms data into an unreadable format, making it unintelligible to anyone without the correct decryption key. This directly addresses the goal of ensuring that if the infrastructure is compromised, the sensitive data remains unreadable and unusable to unauthorized parties.
Why the other options are wrong
- B. ACLs restrict access to resources but don't protect data if access controls are bypassed or compromised.
- C. Network Segmentation isolates parts of a network to limit breach scope, but doesn't protect data itself if accessed.
- D. IDS detects malicious activity but doesn't inherently protect data from being read if a breach occurs.
Encryption
The process of converting information or data into a code to prevent unauthorized access, making it unreadable without the correct key.
- Protects data at rest and in transit.
- Uses algorithms and cryptographic keys.
- Essential for confidentiality and data privacy.
Memory trick: Encryption is like putting your secret message in a locked box that only those with the right key can open.