CompTIA SecurityX (CAS-005)Security EngineeringHard
A financial services organization is migrating its sensitive data storage to a multi-cloud environment. To meet stringent regulatory compliance requirements (e.g., GDPR, PCI DSS), they must ensure that cryptographic keys used for data encryption are managed with the highest level of security, including strict access controls, auditing, and protection against exfiltration. Which key management solution offers the BEST combination of security, control, and compliance for this scenario?
- ASoftware-based Key Management System (KMS)
- BCloud Provider's Default Encryption
- CClient-Side Encryption with self-managed keys
- DHardware Security Module (HSM)
Show answer & explanationAnswer & explanation
Correct answer: D. Hardware Security Module (HSM)
A Hardware Security Module (HSM) provides the highest level of security for cryptographic key management by storing and processing keys within a tamper-resistant hardware device. This offers strong protection against exfiltration, robust access controls, and comprehensive auditing, which are critical for stringent financial regulatory compliance.
Why the other options are wrong
- A. Software-based KMS offers flexibility but lacks the physical tamper-resistance and strong FIPS certifications of an HSM, making it less suitable for the highest compliance levels for sensitive financial data.
- B. Cloud provider's default encryption is convenient but the keys are typically managed by the cloud provider, which may not meet the specific control and audit requirements for highly sensitive financial data under strict regulations.
- C. Client-side encryption with self-managed keys places the burden of key management entirely on the organization, which can be complex and prone to errors, potentially undermining compliance if not implemented perfectly.
Hardware Security Module (HSM)
A physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing. Keys are generated and stored within the HSM and are never exposed outside its secure boundary.
- Provides FIPS 140-2 Level 3 or higher certification.
- Tamper-resistant hardware for key protection.
- Offers high-performance cryptographic operations.
Memory trick: HSM Holds Sensitive Keys Securely.