Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A financial institution is implementing a new system for managing customer accounts. They need to ensure that even if an attacker gains access to the database containing sensitive customer information, the data itself remains unreadable and unusable without a specific key. Which security measure should they prioritize to achieve this goal?
- AFirewall Rules
- BNetwork Segmentation
- CData Encryption at Rest
- DMulti-Factor Authentication
Show answer & explanationAnswer & explanation
Correct answer: C. Data Encryption at Rest
Data encryption at rest encrypts the data while it is stored on a disk or in a database, making it unreadable to unauthorized individuals even if they bypass other security controls and directly access the storage.
Why the other options are wrong
- A. Firewall Rules control network traffic but don't protect data once it's accessed or if the storage itself is compromised.
- B. Network Segmentation isolates parts of the network but doesn't make data unreadable if the segment is breached.
- D. Multi-Factor Authentication secures access to the system, but if an attacker bypasses it and accesses the database directly, the data would still be readable without encryption.
Data Encryption at Rest
Data encryption at rest is the practice of encrypting data when it is stored on persistent storage media, such as hard drives, databases, or cloud storage, to protect it from unauthorized access.
- Protects data when it's not actively being used or transmitted.
- Makes data unreadable without the associated decryption key.
- Crucial for compliance and data breach mitigation.
Memory trick: Data is encrypted while resting, moving, or processing.