SY0-701 exam dumps

SY0-701 practice question 214 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 214

Single answer3.3 Compare and contrast concepts and strategies to protect data.

A healthcare company is moving archived patient records from an on-premises file server to a cloud object storage platform. The records must remain unreadable to the cloud provider's personnel, and the company must be able to cryptographically erase the data quickly if a legal hold expires. Administrators also want to minimize the risk of exposing encryption keys if the storage account is compromised. Which solution BEST meets these requirements?

  1. A

    Encrypt the records on the client side before upload using company-controlled keys stored in an HSM, and upload only the ciphertext to the cloud storage service

  2. B

    Enable server-side encryption with provider-managed keys so the cloud platform transparently encrypts all stored records at rest

  3. C

    Hash each record with SHA-256 before uploading so the cloud provider cannot read the contents, and keep the hashes on-premises

  4. D

    Use transport encryption with TLS 1.3 during upload and rely on the cloud storage platform's access control lists to protect the records after they are stored

Show answer and explanation

Correct answer: A

Explanation

The best answer is client-side encryption with customer-controlled keys in an HSM because it aligns with multiple data protection concepts in Security+ Domain 3.3: protecting data at rest, strong key management, and cryptographic erasure. In cloud scenarios, the distinction between provider-managed encryption and customer-controlled encryption is critical. If the organization must ensure that the cloud provider cannot read the data, encrypting before upload is the strongest approach because plaintext is never entrusted to the provider. NIST guidance on storage encryption and key management consistently emphasizes that the security of encrypted data depends heavily on who controls the keys and how they are protected. Using an HSM is a best practice for safeguarding high-value cryptographic keys. Cryptographic erasure is achieved by securely destroying the encryption keys, rendering encrypted data unreadable without needing to overwrite every stored copy. By contrast, server-side encryption with provider-managed keys improves baseline security but does not provide the same assurance of provider inaccessibility or customer-directed key destruction.

  • A. Correct.

    Correct. Client-side encryption with organization-controlled keys best satisfies all stated requirements. Because encryption occurs before data is uploaded, the cloud provider stores only ciphertext and cannot read the plaintext without access to the customer's keys. Storing keys in a hardware security module (HSM) helps protect key material from compromise and supports strong key management practices. This approach also supports cryptographic erasure: if the encrypted data encryption keys are securely destroyed or made permanently inaccessible, the stored ciphertext becomes effectively unrecoverable. This is a common strategy for protecting highly sensitive regulated data in cloud environments.

  • B. Incorrect.

    Incorrect. Server-side encryption with provider-managed keys protects data at rest from physical media theft and some storage-layer threats, but the provider controls the encryption process and keys. That means provider personnel or services with appropriate access could potentially decrypt the data. It also does not best support the requirement that the records remain unreadable to the provider's personnel, and cryptographic erasure is less directly controlled by the customer.

  • C. Incorrect.

    Incorrect. Hashing is not a substitute for encryption. A cryptographic hash is a one-way integrity mechanism used to detect changes, not to preserve confidentiality while allowing later recovery of the original content. If the company hashed the records instead of encrypting them, it would lose the ability to retrieve the original patient data from the cloud. This distractor targets the common misconception that hashing and encryption are interchangeable for data protection.

  • D. Incorrect.

    Incorrect. TLS protects data in transit between the client and the cloud service, but not necessarily once the data is stored. Access control lists can restrict who is authorized to access stored data, but they do not make the provider unable to read plaintext data if it is stored unencrypted or decrypted server-side. This option addresses transport security and authorization, but it does not meet the core confidentiality and cryptographic erasure requirements.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam