Which method should be used to ensure data is encrypted while at rest on premises in a cloud storage offering?

Prepare for the CompTIA Cloud+ Exam with our comprehensive test. Enhance your skills with multiple choice questions, detailed hints, and explanations. Ace your test!

Multiple Choice

Which method should be used to ensure data is encrypted while at rest on premises in a cloud storage offering?

Explanation:
Encrypting data at rest means protecting stored data with strong encryption applied by the storage layer, along with secure key management. SSL (TLS) protects information as it travels between clients and storage, not once it’s stored on disk. It does not encrypt data at rest. The other options don’t provide encryption either: HMAC is for integrity/authentication, not encryption; SHA is a hashing function, not encryption; RC4 is a legacy cipher that is no longer considered secure for modern use. To truly safeguard data at rest on premises in a cloud storage offering, enable encryption at rest (for example, AES-256) with robust key management (on-premises KMS or HSM). Use SSL/TLS separately to protect data in transit.

Encrypting data at rest means protecting stored data with strong encryption applied by the storage layer, along with secure key management. SSL (TLS) protects information as it travels between clients and storage, not once it’s stored on disk. It does not encrypt data at rest. The other options don’t provide encryption either: HMAC is for integrity/authentication, not encryption; SHA is a hashing function, not encryption; RC4 is a legacy cipher that is no longer considered secure for modern use. To truly safeguard data at rest on premises in a cloud storage offering, enable encryption at rest (for example, AES-256) with robust key management (on-premises KMS or HSM). Use SSL/TLS separately to protect data in transit.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy