Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium
A cloud customer is storing sensitive customer data in a database. They want to prevent sensitive fields (e.g., credit card numbers, social security numbers) from appearing in plain text in database logs, even if the application processes them in cleartext temporarily. The solution must not significantly impact application performance or require extensive code changes. Which data protection technique is most appropriate for this scenario?
- AField-Level Encryption
- BData Masking
- CHomomorphic Encryption
- DTokenization
Show answer & explanationAnswer & explanation
Correct answer: A. Field-Level Encryption
Field-level encryption encrypts specific sensitive fields within a database, ensuring they are stored in ciphertext. This directly prevents them from appearing in plain text in logs while allowing the application to process them after decryption, without requiring changes to the entire database schema or application logic.
Why the other options are wrong
- B. Data masking replaces sensitive data with fictitious data, typically used for non-production environments, not for protecting live production data from appearing in logs while still being processed by the application.
- C. Homomorphic encryption allows computations on encrypted data without decrypting it, but it's computationally intensive and typically used for advanced analytics, not just preventing log exposure.
- D. Tokenization replaces sensitive data with a token, often changing the data format, which might require more application changes than simply encrypting a field.
Field-Level Encryption
A data protection technique where specific sensitive fields within a database or application are individually encrypted, rather than encrypting the entire database or data set. This allows for granular protection and control over sensitive elements.
- Encrypts individual database fields.
- Granular control over sensitive data.
- Prevents cleartext exposure in logs/storage.
Memory trick: Fields Encrypted, Logs are Clean.