Encryption
At rest, in transit, and at the application layer — three different threats.
4 to work through
-
beginner Multiple choice
An attacker obtains the application's database credential from a leaked environment file and runs a SELECT against the customer table. Every volume is encrypted at rest with a managed key service and every connection uses TLS. What does that encryption prevent here?
3 min answer -
intermediate Multiple choice
A regulator asks whether customer data is encrypted. The team says yes, disks are encrypted. Is that a sufficient answer?
2 min answer -
intermediate Multiple choice
Your database is encrypted at rest. An attacker obtains valid application credentials. What does the encryption protect against?
2 min answer -
advanced
A file storage platform encrypts data at rest and in transit. A customer asks whether the provider can read their files. What does the honest answer depend on, and what would change it?
2 min answer
2 terms in this topic
Encryption
Protecting data in transit, at rest and in use — where key management is the actual architecture and the cipher choice is the easy part.
patternField-Level Encryption
Encrypting specific sensitive fields in the application before they reach the datastore, so the store never holds plaintext.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.