CV0-004 Security Practice Question
An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Encryption at rest
Encryption at rest protects data stored on disk, typically using AES-256.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption in transit
Why it's wrong here
Encryption in transit protects data moving across networks via TLS, leaving data unencrypted at rest on disk. It would be correct if the requirement were securing data between the client and cloud service. At-rest protection requires server-side or client-side encryption of stored volumes and objects.
- ✓
Encryption at rest
Why this is correct
Encryption at rest protects data written to persistent storage, such as cloud disks and object stores, by encrypting it before it is saved. This directly satisfies the requirement that sensitive data remain encrypted while stored on disk.
- ✗
Hashing
Why it's wrong here
Hashing is a one-way function producing a fixed digest for integrity verification, and cannot be reversed to recover the original data. It would be correct if the requirement were detecting tampering or storing password verifications. Confidentiality of stored data requires reversible encryption with managed keys.
- ✗
Tokenization
Why it's wrong here
Tokenization replaces sensitive data with tokens, not the same as encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.