ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

An organization is deploying a new cloud-based customer relationship management (CRM) system. As part of its security design, all data at rest within the cloud provider's storage will be encrypted using customer-managed encryption keys (CMEK). All data in transit will be encrypted using TLS 1.3. Which resource protection technique is being implemented for the data at rest?

  1. AData Loss Prevention (DLP)
  2. BAccess Control
  3. CData Masking
  4. DCryptography
Show answer & explanation

Correct answer: D. Cryptography

Encrypting data at rest using customer-managed encryption keys is a direct application of cryptography. Cryptography is the practice and study of techniques for secure communication in the presence of adversarial behavior.

Why the other options are wrong

  • A. DLP aims to prevent data from leaving the organization's control, which is different from protecting data already stored.
  • B. Access Control manages permissions to resources, but encryption protects the data itself regardless of access control bypass.
  • C. Data Masking obscures sensitive data with realistic, but false, data, typically for non-production environments, not for securing production data at rest.

Cryptography

Cryptography is the science of secure communication, focusing on methods to protect information and communications through the use of codes, so that only those for whom the information is intended can read and process it.

  • Used for confidentiality, integrity, and non-repudiation.
  • Involves encryption, decryption, hashing, and digital signatures.
  • Essential for protecting data at rest, in transit, and in use.

Memory trick: CIA ensures data's security, Cryptography is the key.

More Security Operations questions