問題文
An insurer encrypts its claims database at rest and reports that customer data is protected. A claims handler with normal application access then exports 60,000 records and sells them. What does this outcome show about the control?
選択肢
- The control worked exactly as it was intended to, so the insurer's report to its regulator about the protection of customer data remains accurate.
- Encryption at rest defends against someone reading the storage directly and it has no effect on a person who reaches the data through the application, because the application decrypts for every authorized request.
- The handler must have obtained administrative rights, because an ordinary application user cannot export a large number of records from a database that has been encrypted at rest by the insurer's platform.
- The encryption was implemented at the wrong layer because a correctly designed scheme encrypts each record with a key held by the customer, so the handler could not have read the exported records.