Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

An organization is preparing for a potential data breach. They want to ensure that even if an attacker gains access to their systems, the sensitive data remains unreadable and unusable. Which security control directly addresses this objective?

  1. AFirewall
  2. BIntrusion Detection System (IDS)
  3. CAccess Control Lists (ACLs)
  4. DEncryption
Show answer & explanation

Correct answer: D. Encryption

Encryption is the process of transforming data into an unreadable format, making it unusable to unauthorized individuals even if they gain access to it. This directly fulfills the objective of rendering sensitive data unreadable post-breach.

Why the other options are wrong

  • A. A firewall controls network traffic, preventing unauthorized access, but doesn't protect data if the perimeter is breached.
  • B. An IDS detects malicious activity, but doesn't prevent data from being read if accessed.
  • C. ACLs restrict access, but if bypassed or misconfigured, data remains readable.

Encryption

The process of transforming information (plaintext) into a coded, unreadable format (ciphertext) to prevent unauthorized access. It is a fundamental method for protecting data confidentiality and integrity, especially in transit and at rest.

  • Renders data unreadable without the decryption key.
  • Protects data at rest and in transit.
  • Crucial for data confidentiality post-breach.

Memory trick: Encryption: Like a secret code that makes your diary unreadable to anyone without the key.

More Describe the concepts of security, compliance, and identity questions