CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud architect is designing a solution for a highly sensitive application that requires all data at rest to be encrypted. The organization has a strict compliance mandate to maintain full control over the cryptographic keys. Which key management strategy BEST meets this requirement?
- AServer-Side Encryption (SSE) with service-managed keys
- BCustomer-Provided Encryption Keys (CPEK)
- CCloud Provider Managed Keys
- DCustomer Managed Keys (CMK) with Hardware Security Module (HSM) protection
Show answer & explanationAnswer & explanation
Correct answer: D. Customer Managed Keys (CMK) with Hardware Security Module (HSM) protection
Customer Managed Keys (CMK) with Hardware Security Module (HSM) protection provides the customer with full control over the cryptographic keys, including their generation, storage, and lifecycle, while leveraging the security of an HSM.
Why the other options are wrong
- A. SSE with service-managed keys implies the cloud provider manages the keys, which does not meet the customer's requirement for full control.
- B. CPEK involves the customer providing the key, but the cloud provider still manages its use, which might not meet 'full control' over the key's lifecycle.
- C. Cloud Provider Managed Keys means the cloud provider has full control over the keys, not the customer.
Customer Managed Key (CMK) with HSM
An encryption key management strategy where the customer generates and controls their encryption keys, often using a Hardware Security Module (HSM) for enhanced security and control, even when the data is stored in the cloud.
- Customer retains full control over key lifecycle.
- HSMs provide tamper-resistant hardware for key storage.
- Meets stringent compliance requirements for key ownership.
Memory trick: My Keys, My Rules: HSM is the ultimate lockbox.