CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security engineer needs to implement a solution that ensures all data at rest in a new object storage bucket is encrypted using keys managed exclusively by the customer, not the cloud provider. The customer requires full control over the key lifecycle, including generation, rotation, and revocation. Which encryption option should the engineer recommend?
- AServer-Side Encryption with Cloud-Managed Keys (SSE-C)
- BClient-Side Encryption with Customer-Provided Keys
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DServer-Side Encryption with Customer-Managed Keys (SSE-KMS)
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Encryption with Customer-Provided Keys (SSE-C)
Server-Side Encryption with Customer-Provided Keys (SSE-C) allows the customer to provide their own encryption keys to the cloud provider, who then uses these keys to encrypt and decrypt objects on the server side. This gives the customer full control over the key lifecycle, as the keys are never stored by the cloud provider.
Why the other options are wrong
- A. SSE-C involves customer-provided keys, but the option name is incorrect for 'Cloud-Managed Keys'.
- B. Client-Side Encryption means the data is encrypted before being sent to the cloud, which is different from server-side encryption with customer-provided keys.
- D. SSE-KMS uses keys managed by a cloud Key Management Service, meaning the cloud provider has some level of control over the keys, which contradicts the requirement for *exclusive* customer management.
Server-Side Encryption with Customer-Provided Keys (SSE-C)
An encryption method where the customer provides their own encryption keys to the cloud service, which then uses these keys to encrypt and decrypt data at rest on the server side.
- Customer provides the encryption key for each object operation.
- Cloud provider does not store the customer-provided key.
- Offers exclusive customer control over key lifecycle for data at rest.
Memory trick: SSE-C: Customer's Secret, Cloud Encrypts.