Protect the same field in three states and find the gap

short · 40 min · Objective 3.3

Task

Take one sensitive field and protect it at rest, in transit and in use, then show which of the three is genuinely hard — and why the first two answers are wrong when the question is about processing.

Steps

  1. Generate /tmp/customers.csv with twenty synthetic rows and the header id,name,card -- the third column is the sensitive field, and every value in it starts 4471 (synthetic numbers, never real ones). The Verify looks for exactly those: the first row's card in the ciphertext, and 4471 on the wire.
  2. At rest: encrypt the file with openssl enc -aes-256-cbc -pbkdf2 and confirm the sensitive values are no longer findable in the ciphertext.
  3. In transit: first serve the decrypted file over PLAIN HTTP between your two lab VMs, capturing to /tmp/transit-plain.pcap, and confirm 4471 is visible -- that proves the capture can see the values. Then serve it over an encrypted channel, capturing to /tmp/transit.pcap, and confirm they are not visible on the wire.
  4. In use: write a small program that decrypts and processes the data, then — while it is running — inspect its memory with gcore or by reading /proc/<pid>/maps and the corresponding memory, and find the plaintext.
  5. Record in /tmp/states.md that the values were recoverable from a running process despite both other controls being correct.
  6. Write the three controls that actually address the in-use case, and mark which of them your lab could implement and which it could not.

Files the Verify reads

The Verify block reads these by name, so save them exactly here:

  • /tmp/customers.enc -- the encrypted copy from step 2: openssl enc -aes-256-cbc -pbkdf2 -in /tmp/customers.csv -out /tmp/customers.enc.
  • /tmp/transit.pcap -- the capture from step 3, taken while the file crossed the encrypted channel.

Verify

grep -c "$(head -2 /tmp/customers.csv | tail -1 | cut -d, -f3)" /tmp/customers.enc || echo "0 (absent from ciphertext: correct)"
tshark -r /tmp/transit-plain.pcap -Y 'frame contains "4471"' 2>/dev/null | wc -l   # must be above 0: the capture can see it
tshark -r /tmp/transit.pcap -Y 'frame contains "4471"' 2>/dev/null | wc -l         # must be 0: encrypted
grep -ciE "in use|memory|enclave|tokenis|access control" /tmp/states.md

The first must be 0 — the value is not in the ciphertext. The second must be above 0: the plain-HTTP capture shows the values, which proves the capture and the filter can see them -- without it, a 0 on the third line proves nothing. The third must be 0 — encrypted, the values are not on the wire. The fourth must be at least three, because the write-up has to name the in-use controls; if a candidate's answer to 'protect data while it is being processed' is encryption at rest or in transit, the exam question is already lost.

Notes

The memory inspection is the whole lab. Both conventional controls were correctly applied and the plaintext was still recoverable, because the application must see the data to work with it. That is why enclaves, tokenisation and access control are the real answers to the in-use state.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.