Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?

⚠ Common exam trap

The trap here is assuming that transparent data encryption protects against database compromise, when it only protects data at rest and does not prevent access once the database is running.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application-level encryption with deterministic encryption for the searchable field

Application-level encryption with deterministic encryption for the searchable field ensures that data is encrypted before storage and remains unreadable if the database is compromised. Deterministic encryption allows equality searches on that field without decrypting the entire dataset. Other methods either leave data readable in memory, prevent searching, or introduce a separate high-value target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transparent data encryption (TDE) on the database

    Why it's wrong here

    TDE encrypts data at rest at the storage layer, but once the database is running, data is decrypted in memory and accessible to anyone with database access. If an attacker compromises the database, they can read the data. TDE also does not support searching on encrypted fields without decrypting the entire dataset, so it fails both requirements.

  • ✗

    Hashing the sensitive data with a salt

    Why it's wrong here

    Hashing is a one-way function and cannot be reversed to recover the original data. While it protects confidentiality, it makes the data unusable for any purpose other than verification. It also does not support searching on the original value in a meaningful way, and salting prevents equality searches. Therefore, it does not meet the requirements.

  • ✓

    Application-level encryption with deterministic encryption for the searchable field

    Why this is correct

    Application-level encryption ensures data is encrypted before it reaches the database, so a database compromise yields only ciphertext. Using deterministic encryption for the searchable field allows equality searches because the same plaintext always produces the same ciphertext. This meets both the confidentiality and searchability requirements, making it the correct approach.

  • ✗

    Tokenization of all sensitive fields with a centralized token vault

    Why it's wrong here

    Tokenization replaces sensitive data with tokens, but the token vault becomes a high-value target; if compromised, the attacker can detokenize. It also typically does not support searching on the original data unless the vault provides a searchable index, which can introduce complexity and latency. The scenario requires the data to remain unreadable even if the database is compromised, and tokenization may not fully meet that if the vault is separate but also compromised.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.