An e-commerce platform uses Cloud SQL for MySQL to store user profiles and order history. The security team wants to ensure that database administrators (DBAs) cannot view plaintext credit card numbers stored in the database. They also want to minimize application changes. What should they do?
Trap 1: Implement column-level encryption using Cloud KMS in the…
This requires significant application changes and does not leverage built-in DLP capabilities.
Trap 2: Grant DBAs the Cloud SQL Viewer role to restrict access to data.
The Viewer role allows viewing data; it does not mask sensitive columns.
Trap 3: Use Cloud SQL Proxy to encrypt connections and limit DBA access.
Cloud SQL Proxy provides encrypted connections but does not mask data from DBAs.
- A
Implement column-level encryption using Cloud KMS in the application layer.
Why it fails: This requires significant application changes and does not leverage built-in DLP capabilities.
- B
Grant DBAs the Cloud SQL Viewer role to restrict access to data.
Why it fails: The Viewer role allows viewing data; it does not mask sensitive columns.
- C
Use Cloud SQL Proxy to encrypt connections and limit DBA access.
Why it fails: Cloud SQL Proxy provides encrypted connections but does not mask data from DBAs.
- D
Use Cloud DLP with de-identification and re-identification transforms on the Cloud SQL database.
Cloud DLP can automatically detect and tokenize sensitive data, with re-identification for authorized apps.