QuestionQ54

Adversarial Tactics, Techniques, and Procedures

An organization’s vendor-hosted database environment is encrypted both at rest and in transit. The database was accessed and critical data was stolen. Which of the following is the MOST likely cause?

  • A Improper backup procedures
  • B Use of group rights for access
  • C Misconfigured access control list (ACL)
  • D Insufficiently strong encryption
Explanation

Encryption at rest and in transit does not restrict access by an identity that has been incorrectly authorized. A misconfigured access control list (ACL) can grant unauthorized access to the database and allow data theft despite encryption protections.

Community Discussion

No comments yet. Be the first to start the discussion!