CRISC Exam QuestionsBrowse all questions from this exam

CRISC Exam - Question 1105


Which of the following is the BEST way to protect sensitive data from administrators within a public cloud?

Show Answer
Correct Answer: C

Encrypting data before it leaves the organization ensures that the data is protected from unauthorized access at all stages, including transit and storage within the public cloud. This method guarantees that only the organization holds the encryption keys needed to decrypt the data, thereby protecting it even from administrators within the cloud provider's environment. Encrypting data solely within the cloud or encrypting physical hard drives addresses only specific parts of the data lifecycle and could still expose the data to certain risks from high-level administrators.

Discussion

7 comments
Sign in to comment
john_boogiemanOption: C
Aug 20, 2023

Encrypting the data before it leaves the organization is the BEST way to protect sensitive data from administrators within a public cloud. When data is encrypted before leaving the organization, the data remains encrypted while it is stored in the cloud, and only authorized parties with the encryption keys can access the decrypted data. This means that even if cloud administrators gain access to the data, they would only be able to see the encrypted version and not the sensitive data in clear text.

MartyMar
Jul 12, 2023

I would think C would be the correct answer. If it is encrypted before it gets to the cloud. You wouldn't need to encrypt it on the Cloud Database

Broesweelies
Sep 30, 2023

Its A. Read the question, you assume it comes from on prem but the question states the data resides in public cloud. Just encrypt the data itself so the admins cant access it.

CbtLOption: C
Oct 30, 2023

Agree with C.

mynk29Option: A
Nov 13, 2023

How do you define 'organisation'? are systems running in someone elses' organisation? Boundary of the organisation is defined as things which are in control of organisation including onprem and cloud systems. Also- You can encrypt the data in cloud with your own key so admins of cloud cannot see decrypt it. I say this

mynk29
Nov 13, 2023

sorry for typos.. wrote in hurry. :)

FredDurstOption: C
Jun 25, 2024

The BEST way to protect sensitive data from administrators within a public cloud is C. You retain full control over the encryption keys and algorithms, ensuring the confidentiality of your data even within the cloud provider's environment. A is incorrect, while it protects data at rest, cloud administrators with high-level access could still decrypt or bypass those safeguards.

c445ac5Option: A
Feb 24, 2025

Not sure what "before it leaves the organization" means if the data resides in the public cloud to begin with