CompTIA SecurityX (CAS-005)Security ArchitectureHard
A security architect is tasked with ensuring the confidentiality and integrity of data at rest in a multi-tenant cloud storage service. The solution must prevent the cloud provider from accessing the unencrypted data, even with full administrative privileges. Which data security strategy should the architect recommend?
- AClient-side encryption before data is uploaded to the cloud.
- BData masking for sensitive fields within the storage.
- CCloud provider-managed encryption with customer-managed keys (CMK).
- DVPC endpoints to secure data transfer to the cloud storage.
Show answer & explanationAnswer & explanation
Correct answer: A. Client-side encryption before data is uploaded to the cloud.
Client-side encryption ensures that data is encrypted before it leaves the customer's control and is never exposed to the cloud provider in an unencrypted state. This provides the strongest guarantee against cloud provider access, as the encryption keys remain solely with the customer.
Why the other options are wrong
- B. Data masking alters sensitive data to make it unusable but does not encrypt the original data at rest or prevent the cloud provider from accessing the original, unmasked data if not combined with encryption.
- C. While CMK gives customers control over the keys, the encryption/decryption process is still performed by the cloud provider's service, meaning the provider's infrastructure has access to the unencrypted data during operations.
- D. VPC endpoints secure the network path to cloud services but do not encrypt the data itself or prevent the cloud provider from accessing unencrypted data once stored.
Client-Side Encryption
Client-side encryption is the process of encrypting data on the client's system before it is transmitted to or stored by a third-party service, such as a cloud provider.
- Keys are managed solely by the client.
- Data is never unencrypted in the cloud provider's environment.
- Provides maximum control over data confidentiality from the cloud provider.
Memory trick: To keep your cloud data truly secret, encrypt it before it even touches the cloud's hands.