CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security architect is designing a key management strategy for a multi-tenant SaaS application that stores data for various customers. Each customer's data must be encrypted using a unique key, and the application needs to perform cryptographic operations without direct access to the master keys. Which key management service feature would best meet these requirements?

  1. AEnvelope Encryption
  2. BBring Your Own Key (BYOK)
  3. CHardware Security Module (HSM)
  4. DKey Rotation
Show answer & explanation

Correct answer: A. Envelope Encryption

Envelope encryption uses a data encryption key (DEK) to encrypt customer data, and a master key (Key Encryption Key or KEK) to encrypt the DEK. This allows the application to use and manage DEKs without direct access to the sensitive master keys, fulfilling the multi-tenant and secure operation requirements.

Why the other options are wrong

  • B. BYOK allows customers to import their own keys, but doesn't inherently solve the problem of unique keys per tenant or the application's limited master key access for cryptographic operations.
  • C. An HSM provides a secure, tamper-resistant environment for generating, storing, and managing cryptographic keys but is a hardware component that might underpin a KMS, not a feature directly solving the multi-tenant unique key and application access problem in this context.
  • D. Key rotation is a security best practice for periodically changing keys but doesn't directly address the multi-tenant unique key requirement or the tiered access for cryptographic operations.

Envelope Encryption

A method where data is encrypted with a data encryption key (DEK), and the DEK itself is then encrypted with a key encryption key (KEK), providing layered security and access control.

  • Uses both DEK and KEK
  • KEK encrypts the DEK
  • Application uses encrypted DEK for data operations

Memory trick: Keys within keys, like an encrypted envelope for your secrets.

More Security questions