CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security engineer is configuring encryption for a new object storage bucket containing highly confidential data. The organization's policy dictates that only authorized applications, and not human users, should have direct access to the encryption keys. Which IAM mechanism, when combined with encryption-at-rest provided by the cloud provider, would BEST enforce this policy?
- AGranting IAM roles directly to the applications with specific key usage permissions.
- BUtilizing a Cloud Access Security Broker (CASB) to filter key access requests.
- CImplementing a strong password policy for all human users.
- DStoring encryption keys in a customer-managed Hardware Security Module (HSM).
Show answer & explanationAnswer & explanation
Correct answer: A. Granting IAM roles directly to the applications with specific key usage permissions.
Granting IAM roles directly to applications with specific key usage permissions ensures that only the applications, authenticated via their assigned roles, can access the encryption keys, thereby preventing human users from direct access, as per the policy.
Why the other options are wrong
- B. CASBs focus on monitoring and enforcing policies for cloud service usage, but direct key access control for applications is handled by the cloud provider's native IAM.
- C. A strong password policy is for human user authentication, but the policy specifically wants to prevent human users from direct key access, regardless of password strength.
- D. While HSMs provide strong key protection, they don't inherently restrict access to only applications versus human users; access control still needs to be managed, typically via IAM.
IAM Roles for Applications
A cloud identity and access management feature that allows applications or services to assume specific roles with defined permissions, enabling secure access to other cloud resources without embedding credentials.
- Provides temporary credentials for applications.
- Enforces the principle of least privilege for programmatic access.
- Key for securing communication between cloud services.
Memory trick: Roles for bots, not humans, to touch the key.