Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The organization wants to minimize the impact on application performance and avoid modifying the application code. Which of the following should the architect implement?

⚠ Common exam trap

A common mix-up: candidates confuse encryption in transit with encryption at rest; TLS protects data on the wire, not on disk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent data encryption (TDE) at the database level

Transparent data encryption encrypts database files at rest without requiring application changes, providing confidentiality and integrity with minimal performance impact. It is specifically designed for the scenario's constraints, unlike application-level encryption or transit encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application-level encryption of each field before storage

    Why it's wrong here

    Application-level encryption requires modifying application code to encrypt and decrypt fields, which violates the requirement to avoid code changes. It can also impact performance and complicate queries. While it provides strong confidentiality, it does not meet the transparency requirement.

  • ✗

    Full disk encryption (FDE) on the database server's storage volumes

    Why it's wrong here

    FDE encrypts the entire disk, including the operating system and database files, but it only protects data when the system is powered off. Once the server is running and the disk is unlocked, data is accessible. It does not provide the same level of at-rest protection for the database files specifically when the system is online.

  • ✓

    Transparent data encryption (TDE) at the database level

    Why this is correct

    TDE encrypts data at rest at the database file level and is transparent to applications, requiring no code changes. It protects confidentiality if storage media is stolen and maintains integrity through encryption. Performance impact is generally low because encryption is handled by the database engine.

  • ✗

    Network encryption using TLS for all database connections

    Why it's wrong here

    TLS protects data in transit between clients and the database, not data at rest on the server. It does not address the confidentiality of stored data if the storage media is compromised. Therefore it does not meet the at-rest encryption requirement.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.