Tyscorpa Study resources Open the Academy

Data Protection

Data classification, states of data, DLP, rights management, and data sovereignty.

SY0-701 Obj. 3.3 Security Architecture 18% of the exam

Data Classifications

Government / MilitaryCommercial EquivalentDescription
Top SecretRestricted / ConfidentialHighest sensitivity; unauthorized disclosure causes grave damage
SecretPrivate / SensitiveSerious damage if disclosed
ConfidentialInternalDisclosure could damage the organization
UnclassifiedPublicSafe for public release

Data ownership: Data owner (business executive responsible for classification) → Data steward (enforces policies) → Data custodian (IT admin who implements controls) → Data subject (individual the data is about).

States of Data

StateDefinitionControls
Data at RestStored on persistent media (disk, database, cloud storage)Full disk encryption (FDE), database encryption (TDE), file encryption (EFS)
Data in TransitMoving across a network connectionTLS, IPsec, VPN, HTTPS, SSH
Data in Use / in ProcessingLoaded into volatile memory (RAM, CPU cache)Secure enclaves (Intel SGX), memory encryption, access controls

Data Loss Prevention (DLP)

DLP systems monitor, detect, and block unauthorized transmission of sensitive data.

DLP Use Case Example:
A hospital configures email DLP to scan outbound messages for patterns matching SSNs and ICD-10 medical codes. When detected, the email is blocked and the security team is alerted. A staff member who accidentally attaches a patient file to an external email receives an automated warning.

Digital Rights Management (DRM) / IRM

Data Sovereignty & Residency

Secure Data Destruction

MethodDescriptionBest For
Overwriting / WipingMultiple passes of random data over storageHDDs being repurposed (NIST 800-88)
DegaussingStrong magnetic field destroys magnetic mediaHDDs, magnetic tape
Cryptographic ErasureDelete the encryption key — data becomes unreadable (crypto-shredding)Cloud storage, SSDs, self-encrypting drives
Physical DestructionShredding, crushing, incinerationTop-secret media; SSDs (overwriting is unreliable)
Exam Tip: For SSDs, overwriting is not reliable because of wear leveling — use cryptographic erasure or physical destruction. For cloud data, the only reliable method is cryptographic erasure (destroy the key). For magnetic media: degaussing or physical destruction guarantees no data recovery.

External Resources

PreviousArchitecture Models NextAcronyms - Security Architecture

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy