CAS-004 Security Architecture Practice Question
A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The organization wants to minimize the impact on application performance and avoid modifying the application code. Which of the following should the architect implement?
⚠ Common exam trap
A common mix-up: candidates confuse encryption in transit with encryption at rest; TLS protects data on the wire, not on disk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent data encryption (TDE) at the database level
Transparent data encryption encrypts database files at rest without requiring application changes, providing confidentiality and integrity with minimal performance impact. It is specifically designed for the scenario's constraints, unlike application-level encryption or transit encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application-level encryption of each field before storage
Why it's wrong here
Application-level encryption requires modifying application code to encrypt and decrypt fields, which violates the requirement to avoid code changes. It can also impact performance and complicate queries. While it provides strong confidentiality, it does not meet the transparency requirement.
- ✗
Full disk encryption (FDE) on the database server's storage volumes
Why it's wrong here
FDE encrypts the entire disk, including the operating system and database files, but it only protects data when the system is powered off. Once the server is running and the disk is unlocked, data is accessible. It does not provide the same level of at-rest protection for the database files specifically when the system is online.
- ✓
Transparent data encryption (TDE) at the database level
Why this is correct
TDE encrypts data at rest at the database file level and is transparent to applications, requiring no code changes. It protects confidentiality if storage media is stolen and maintains integrity through encryption. Performance impact is generally low because encryption is handled by the database engine.
- ✗
Network encryption using TLS for all database connections
Why it's wrong here
TLS protects data in transit between clients and the database, not data at rest on the server. It does not address the confidentiality of stored data if the storage media is compromised. Therefore it does not meet the at-rest encryption requirement.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.