🔥 3-day streak
ISACA CDPSE — Certified Data Privacy Solutions Engineer6 / 147
Question 6 of 147

A privacy engineer is designing at-rest encryption for a data lake holding sensitive customer records across multiple business units. Compliance requires that a compromise of the storage layer alone must not expose plaintext, and that cryptographic keys never reside in the same trust boundary as the encrypted data. Which design choice BEST satisfies these requirements?

Reviewed for accuracy · Report an issueNext question