DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy

A security team is auditing an application's data handling practices. The application processes sensitive user data, and regulations require that this data be protected against unauthorized access, even if the underlying storage infrastructure is compromised. Which security best practice specifically addresses the protection of data when it is stored on disk or in a database?

  1. AData in Transit Encryption
  2. BData at Rest Encryption
  3. CIntrusion Detection System (IDS)
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: B. Data at Rest Encryption

Data at Rest Encryption is the process of encrypting data when it is stored on persistent storage, such as hard drives, SSDs, or databases. This ensures that even if storage media are stolen or compromised, the data remains unreadable without the decryption key.

Why the other options are wrong

  • A. Data in Transit Encryption protects data as it moves across networks, not when stored.
  • C. An Intrusion Detection System (IDS) monitors for malicious activity but doesn't encrypt stored data itself.
  • D. Data Loss Prevention (DLP) prevents sensitive data from leaving the organization, but doesn't specifically encrypt data on storage.

Data at Rest Encryption

Data at rest encryption is the cryptographic protection of data when it is stored on non-volatile media, such as databases, file systems, or storage devices.

  • Protects data on disk, in databases, or backups.
  • Renders data unreadable without the decryption key.
  • Crucial for compliance and data breach mitigation.
  • Different from data in transit encryption.

Memory trick: Resting data needs encryption for peace of mind.

More Application Deployment and Security questions