3.3 Compare and contrast concepts and strategies to protect data

Domain 3: Security Architecture

Data protection starts with classification: know data types (regulated, trade secret, intellectual property, legal, financial, human- and non-human-readable) and classifications (sensitive, confidential, public, restricted, private, critical). Then cover the general considerations — data states (at rest, in transit, in use), data sovereignty, and geolocation — and the methods: encryption, hashing, masking, tokenization, obfuscation, segmentation, and permission restrictions. The exam tests state-to-method matching: TLS protects data in transit, full-disk encryption protects data at rest, and data in use is the hard case often addressed by secure enclaves. Distinguish the look-alike methods precisely — tokenization substitutes a non-sensitive placeholder with a lookup, masking hides characters for display, hashing is one-way. Data sovereignty questions hinge on data being subject to the laws of the country where it physically resides, which drives geographic restrictions on storage. Candidates lose easy points by treating masking, tokenization, and encryption as interchangeable.

What you must know

common pitfall · Candidates treat tokenization, masking, and encryption as interchangeable, when the exam expects the specific method matched to the specific use case.

Is objective 3.3 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free