How to Render Sensitive Data at Rest Unreadable?
A company must ensure sensitive data at rest is rendered unreadable. Which of the following will the company most likely use?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It differentiates between reversible confidentiality controls and irreversible integrity checks, trapping candidates who confuse 'unreadable' with 'non-recoverable'.
This question tests the appropriate control for protecting sensitive data at rest by making it unreadable to unauthorized parties. The community overwhelmingly confirms that encryption is the standard solution, as it securely obscures data while allowing authorized recovery via a decryption key.
Candidates frequently choose Hashing or Tokenization, mistakenly believing they serve the same purpose as encryption. However, hashing is strictly one-way and used for integrity, while tokenization replaces data entirely, neither of which allows authorized users to access the original sensitive information when required.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept
Protecting data at rest requires a mechanism that maintains strict confidentiality without permanently destroying the ability to access the original information.Why Encryption is Correct
Encryption utilizes cryptographic algorithms and keys to transform plaintext into ciphertext. This directly satisfies the requirement: the data becomes completely unreadable to attackers, yet remains fully recoverable for legitimate users who hold the correct decryption key. As highlighted by top-voted community comments, encryption is the universally accepted standard for securing stored files, databases, and drives.Why Other Options Are Incorrect
- Hashing is a one-way mathematical function designed for data integrity verification. Because it cannot be reversed, it is fundamentally unsuitable for scenarios requiring future data retrieval.
- Tokenization swaps sensitive values with random, meaningless identifiers. While excellent for PCI-DSS compliance, it relies on external mapping tables rather than cryptographic reversal, and does not technically encrypt the data itself.
- Segmentation divides networks or systems to contain breaches. It provides zero protection against physical or logical theft of storage media containing unencrypted files.
Community Consensus
With a 91% approval rate, candidates consistently recognize that the keyword "unreadable" paired with business continuity needs points exclusively to encryption. The discussion reinforces that Security+ prioritizes reversible confidentiality controls for data-at-rest requirements.Official Reference
- https://www.comptia.org/certifications/security
- NIST SP 800-111r1: Guide to Storage Encryption Technologies for End User Devices
- FIPS PUB 140-3: Security Requirements for Cryptographic Modules
Exam Strategy
Always pay close attention to keywords like "at rest," "in transit," and "unreadable." If the scenario requires data to be obscured but still retrievable by authorized users, encryption is almost always the correct choice over hashing or tokenization.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →