CAS-004 Security Architecture Practice Question
A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?
⚠ Common exam trap
The trap here is assuming that transparent data encryption protects against database compromise, when it only protects data at rest and does not prevent access once the database is running.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application-level encryption with deterministic encryption for the searchable field
Application-level encryption with deterministic encryption for the searchable field ensures that data is encrypted before storage and remains unreadable if the database is compromised. Deterministic encryption allows equality searches on that field without decrypting the entire dataset. Other methods either leave data readable in memory, prevent searching, or introduce a separate high-value target.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transparent data encryption (TDE) on the database
Why it's wrong here
TDE encrypts data at rest at the storage layer, but once the database is running, data is decrypted in memory and accessible to anyone with database access. If an attacker compromises the database, they can read the data. TDE also does not support searching on encrypted fields without decrypting the entire dataset, so it fails both requirements.
- ✗
Hashing the sensitive data with a salt
Why it's wrong here
Hashing is a one-way function and cannot be reversed to recover the original data. While it protects confidentiality, it makes the data unusable for any purpose other than verification. It also does not support searching on the original value in a meaningful way, and salting prevents equality searches. Therefore, it does not meet the requirements.
- ✓
Application-level encryption with deterministic encryption for the searchable field
Why this is correct
Application-level encryption ensures data is encrypted before it reaches the database, so a database compromise yields only ciphertext. Using deterministic encryption for the searchable field allows equality searches because the same plaintext always produces the same ciphertext. This meets both the confidentiality and searchability requirements, making it the correct approach.
- ✗
Tokenization of all sensitive fields with a centralized token vault
Why it's wrong here
Tokenization replaces sensitive data with tokens, but the token vault becomes a high-value target; if compromised, the attacker can detokenize. It also typically does not support searching on the original data unless the vault provides a searchable index, which can introduce complexity and latency. The scenario requires the data to remain unreadable even if the database is compromised, and tokenization may not fully meet that if the vault is separate but also compromised.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.