CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud architect is designing a solution for a highly sensitive application that requires the highest level of assurance for encryption key management. The organization's policy dictates that encryption keys must be generated and stored in a FIPS 140-2 Level 3 compliant hardware module, with direct control over key lifecycle operations (generation, import, deletion) and auditability. Which key management approach should the architect recommend?
- AImplementing a Software Key Management System (KMS) with customer-managed keys.
- BUsing client-side encryption with open-source cryptographic libraries.
- CDeploying a dedicated Hardware Security Module (HSM) as a service.
- DUtilizing cloud provider's default encryption (e.g., SSE-S3).
Show answer & explanationAnswer & explanation
Correct answer: C. Deploying a dedicated Hardware Security Module (HSM) as a service.
A dedicated HSM as a service provides FIPS 140-2 Level 3 compliance for key generation and storage, offering direct customer control over key lifecycle operations and auditability, which aligns with the highest assurance requirements for sensitive applications.
Why the other options are wrong
- A. Software KMS with customer-managed keys offers more control than default encryption but typically does not meet FIPS 140-2 Level 3 hardware security module requirements.
- B. Client-side encryption with open-source libraries places the burden of key management entirely on the client, often lacking the enterprise-grade security controls, FIPS compliance, and auditability required.
- D. Default cloud provider encryption (like SSE-S3) uses provider-managed keys with limited customer control and typically does not offer FIPS 140-2 Level 3 assurance for key storage.
Hardware Security Module (HSM) as a Service
A cloud service offering dedicated, FIPS-compliant hardware for cryptographic key generation, storage, and management, providing high assurance.
- Provides highest level of key security.
- Meets strict compliance standards (e.g., FIPS 140-2 Level 3).
- Customer retains direct control over keys.
Memory trick: FIPS Level 3 needs a dedicated HSM fortress.