Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A financial services firm must protect cardholder data in a database and wants a control that renders the data unreadable to database administrators and to anyone who steals a backup, while still allowing the application to run equality lookups on the protected column. Which approach BEST meets these requirements?

⚠ Common exam trap

The trap here is assuming that strong encryption such as AES-GCM automatically supports searchable equality lookups, when randomized encryption deliberately prevents them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store a keyed hash of the column using HMAC-SHA-256 with a key held outside the database, and query by recomputing the hash of the search value.

A keyed hash computed with a secret key held outside the database is deterministic, so equality predicates can be evaluated directly against the stored digest while the original values stay hidden from administrators and backup thieves. This preserves index-based lookups and satisfies the confidentiality goal, whereas randomized encryption breaks equality queries and static-IV encryption introduces serious cryptographic weaknesses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the column encrypted with AES-256-GCM using a key held in an HSM, and let the application decrypt rows after retrieving them by primary key.

    Why it's wrong here

    Strong authenticated encryption with an HSM-held key protects confidentiality at rest, but randomized encryption produces different ciphertext for identical plaintexts, so the database cannot perform equality lookups on the encrypted column. Retrieval by primary key works, yet the stated requirement to query by the protected value is not satisfied without decrypting the entire table in the application.

  • ✗

    Store the column in plaintext but restrict table access with database roles and enable transparent data encryption on the tablespace.

    Why it's wrong here

    Role-based restrictions and transparent data encryption protect against some access paths, but transparent encryption keys are managed by the database and are available to anyone with sufficient database or storage-level privileges. A stolen backup restored elsewhere or an administrator with key access can read the plaintext values, so the requirement to defeat database administrators is not met.

  • ✓

    Store a keyed hash of the column using HMAC-SHA-256 with a key held outside the database, and query by recomputing the hash of the search value.

    Why this is correct

    A keyed hash is deterministic for a given input and key, so identical values produce identical digests and the database can index and match them for equality searches. Because the key lives outside the database, administrators and backup thieves see only digests they cannot reverse or verify without the key, meeting both the confidentiality and lookup requirements.

  • ✗

    Store the column encrypted with AES-256-CBC using a static initialization vector so identical plaintexts produce identical ciphertext for lookups.

    Why it's wrong here

    Reusing a static initialization vector makes ciphertext deterministic and enables equality matching, but it is a classic cryptographic misuse that leaks equality patterns and enables chosen-plaintext analysis, and CBC provides no integrity protection. The scheme is fragile and would likely fail both a security review and the confidentiality requirement against a determined attacker.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.