SSCP Systems Security Certified PractitionerSystems and Application SecurityHard

A company is implementing a new customer relationship management (CRM) system. To comply with data privacy regulations, all personally identifiable information (PII) stored in the database must be protected even if the database itself is compromised. Which cryptographic control best ensures PII confidentiality at rest in this scenario?

  1. AColumn-level encryption for PII fields within the database.
  2. BHashing sensitive PII data before storage.
  3. CFull disk encryption (FDE) on the database server.
  4. DTransport Layer Security (TLS) for client-server communication.
Show answer & explanation

Correct answer: A. Column-level encryption for PII fields within the database.

Column-level encryption encrypts individual sensitive data fields within the database. If the database is compromised, an attacker might gain access to the database itself, but the PII data within the encrypted columns would remain confidential, provided the encryption keys are stored separately and securely.

Why the other options are wrong

  • B. Hashing provides integrity and can be used for password storage, but it is a one-way function and does not allow for data retrieval, thus it cannot ensure confidentiality of PII that needs to be accessed and read.
  • C. FDE protects the entire disk but is vulnerable if the OS is running and an attacker gains access to the database application.
  • D. TLS protects data in transit, not data at rest within the database.

Column-level Encryption

A method of encrypting specific data columns within a database, rather than the entire database or disk. This provides granular protection for sensitive data fields.

  • Encrypts individual fields or columns.
  • Protects data even if an attacker gains database access.
  • Requires secure key management for effectiveness.

Memory trick: Encrypting data at rest is like putting a safe around your files.

More Systems and Application Security questions