DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy
A company is developing a highly sensitive financial application. They need to ensure that data at rest (e.g., in databases, file storage) is protected from unauthorized access, even if the underlying storage is compromised. Which security best practice is specifically designed to address this requirement?
- ANetwork Segmentation
- BData Encryption at Rest
- CIntrusion Detection System (IDS)
- DTransport Layer Security (TLS)
Show answer & explanationAnswer & explanation
Correct answer: B. Data Encryption at Rest
Data encryption at rest is the practice of encrypting data when it is stored on a physical medium. This ensures that even if the storage is compromised, the data remains unreadable and protected without the decryption key.
Why the other options are wrong
- A. Network segmentation protects data in transit and restricts access, but doesn't protect data once it's stored if the storage itself is compromised.
- C. An IDS monitors for malicious activity but doesn't directly protect data at rest if a compromise occurs.
- D. TLS protects data in transit (over the network), not data stored at rest.
Data Encryption at Rest
The practice of encrypting data when it is stored on any persistent storage medium (e.g., hard drives, databases, cloud storage). It protects data from unauthorized access if the storage device is compromised.
- Protects data on storage mediums.
- Renders data unreadable without decryption key.
- Crucial for sensitive data compliance.
Memory trick: At rest is on disk, in transit is on wire, in use is in memory.