SSCP Systems Security Certified PractitionerSystems and Application SecurityMedium
A cloud architect is designing a new application that will process highly sensitive personal identifiable information (PII). To comply with strict data privacy regulations, the architect must ensure that even if the underlying infrastructure is compromised, the PII remains unreadable. Which of the following data protection concepts is the architect primarily focusing on?
- AData Masking
- BData at Rest Encryption
- CData Minimization
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: B. Data at Rest Encryption
Data at rest encryption ensures that data stored on any persistent storage (disks, databases, backups) remains encrypted and unreadable even if the storage medium itself is compromised or stolen.
Why the other options are wrong
- A. Data masking replaces sensitive data with structurally similar but inauthentic data, often for non-production environments, not for protecting active PII from infrastructure compromise.
- C. Data minimization is about collecting and storing only necessary data, which reduces risk but doesn't make existing data unreadable if compromised.
- D. DLP systems prevent sensitive data from leaving defined boundaries, but don't directly address the unreadability of data already stored if the infrastructure is compromised.
Data at Rest Encryption
The cryptographic protection of data when it is stored on any non-volatile storage medium, such as hard drives, solid-state drives, databases, and backup tapes.
- Protects data when not actively being used or transmitted.
- Ensures data remains unreadable if storage is compromised.
- Commonly implemented via full disk encryption, database encryption, or file-level encryption.
Memory trick: Data sleeps, data moves, data works; each state needs its own security perks.