SY0-701 exam dumps

SY0-701 practice question 215 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 215

Single answer3.3 Compare and contrast concepts and strategies to protect data.

A healthcare company is moving patient billing records from an on-premises file server to a cloud storage platform. The security team must ensure the data remains unreadable if the storage provider is breached, and they also want to reduce the impact if old backup copies are exposed later. The application already uses TLS for data in transit. Which solution BEST addresses these requirements?

  1. A

    Use server-side encryption managed entirely by the cloud provider and rely on TLS for confidentiality

  2. B

    Tokenize sensitive billing fields before uploading the records and maintain the token vault on-premises

  3. C

    Hash the billing records before uploading them so the cloud provider cannot read the data

  4. D

    Apply RAID 6 to the cloud storage volume to improve resilience and protect the records

Show answer and explanation

Correct answer: B

Explanation

The best answer is to tokenize sensitive billing fields before sending them to cloud storage while keeping the token vault under the organization's control. In Security+ data protection objectives, candidates are expected to compare strategies such as encryption, masking, hashing, obfuscation, segmentation, and tokenization. Here, the key requirements are confidentiality even if the storage provider is breached and reduced impact from backup exposure. Tokenization is well suited because the cloud-stored dataset contains tokens instead of the actual sensitive values, limiting exposure. By contrast, provider-managed server-side encryption can be useful, but if the provider controls the keys, it does not best protect against provider compromise. Hashing is inappropriate because billing records must remain usable and recoverable. RAID addresses availability, not data confidentiality. This aligns with common industry guidance to minimize stored sensitive data and separate protected data from the systems that process or store less-sensitive representations.

  • A. Incorrect.

    This is incorrect because server-side encryption controlled entirely by the cloud provider does protect data at rest from some threats, but it does not best satisfy the requirement that data remain unreadable if the provider itself is breached or abused. If the provider manages both the encrypted data and the keys, an attacker who compromises the provider environment may be able to access both. TLS only protects data in transit and does not reduce exposure from stored backups once they exist.

  • B. Correct.

    This is correct because tokenization replaces sensitive data elements with non-sensitive tokens, while the original values are stored separately in a token vault. By keeping the token vault on-premises, the organization ensures that exposed cloud data and old cloud backups do not contain the actual sensitive billing values. This directly supports data protection and minimization strategies by reducing the amount of sensitive data stored in the cloud. It is especially appropriate for structured fields such as account numbers, patient identifiers, and billing details.

  • C. Incorrect.

    This is incorrect because hashing is intended for integrity verification and one-way transformation, not for storing records that must later be retrieved in original form. If the company hashes the billing records, it would not be able to reconstruct the original patient billing data for normal business operations. This reflects a common misconception that hashing is a substitute for encryption or tokenization for recoverable sensitive data.

  • D. Incorrect.

    This is incorrect because RAID provides availability and fault tolerance against disk failures, not confidentiality of sensitive data. It does nothing to make patient billing records unreadable to an attacker and does not address the risk posed by exposed backups. Candidates may choose this if they confuse resilience controls with data protection controls.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam