Soru

Zorluk: KolayCryptographic Concepts and Algorithms

A security administrator needs to ensure that sensitive company data stored on enterprise laptops remains confidential if a laptop is lost or stolen, and must also verify that system configuration files have not been modified. Which of the following cryptographic techniques should the administrator implement to fulfill these requirements? (Select TWO.)

  1. Symmetric bulk encryption (such as AES-256) for data-at-rest protectionCevap
  2. Cryptographic hashing algorithms (such as SHA-256) for integrity checkingCevap
  3. C
    Asymmetric key encryption algorithms for high-speed storage volume encryption
  4. D
    Digital signatures to ensure confidentiality of files stored on local drives
  5. E
    Certificate Signing Requests (CSRs) to perform drive partition encryption

Cevap

Symmetric bulk encryption (such as AES-256) to protect data confidentiality at rest, and cryptographic hashing algorithms (such as SHA-256) to verify configuration file integrity.
Symmetric bulk encryption (such as AES-256) is designed to efficiently protect data at rest on storage media against unauthorized access. Cryptographic hashing algorithms (such as SHA-256) produce unique digests used to verify data integrity by confirming files have not been modified.

Adım Adım Çözüm

1
Identify the cryptographic control required for data confidentiality at rest on stolen hardware.
Symmetric bulk encryption (e.g., AES-256) provides fast and effective encryption for local drives.
Symmetric ciphers use a single secret key for fast encryption and decryption of large volumes of data.
2
Identify the cryptographic control required for verifying configuration file integrity.
Cryptographic hashing algorithms (e.g., SHA-256) generate fixed-size hash values to detect tampering.
Any modification to a configuration file changes its resulting hash digest, indicating a failure of integrity.

Anahtar Kavram

Data-at-Rest Encryption and Hashing for Integrity
Tahmini Süre:1m 0s
Bu soruyu puanla