CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a data security solution for a B2B SaaS platform that handles sensitive customer financial data. The platform uses multiple microservices, and data is stored in various databases (relational, NoSQL). To comply with stringent regulatory requirements (e.g., GDPR, PCI DSS), the architect needs to ensure that data is encrypted at rest and in transit, and that access policies are consistently applied across all data stores. Which architectural pattern provides the most integrated and scalable approach for managing encryption keys and access controls across this diverse environment?

  1. ANetwork-level encryption (TLS) for all database connections.
  2. BPer-service database encryption with application-level key management.
  3. CDistributed ledger technology (DLT) for data integrity.
  4. DCentralized Hardware Security Module (HSM) and Key Management System (KMS).
Show answer & explanation

Correct answer: D. Centralized Hardware Security Module (HSM) and Key Management System (KMS).

A centralized HSM and KMS solution offers a robust and scalable approach to manage encryption keys for data at rest and in transit across diverse data stores. HSMs provide FIPS-compliant hardware for key generation and storage, while KMS manages the lifecycle and access policies for these keys, ensuring consistent application and auditability across the entire platform.

Why the other options are wrong

  • A. Network-level encryption (TLS) secures data in transit but does not address data at rest encryption or the centralized management of encryption keys and access policies for data stores.
  • B. Per-service encryption with application-level key management can lead to inconsistent policies, higher operational overhead, and increased risk of key compromise across a diverse microservices environment.
  • C. DLT is primarily for data integrity and immutability, not for centralizing encryption key management and access controls for diverse database types.

Centralized HSM and KMS

A combined solution using Hardware Security Modules (HSMs) for secure key generation and storage, and a Key Management System (KMS) for managing the lifecycle and access policies of encryption keys.

  • Provides FIPS-compliant hardware protection for cryptographic keys.
  • Centralizes key lifecycle management (generation, rotation, revocation).
  • Enforces consistent access control and auditability for keys across an enterprise.

Memory trick: To keep data safe, you need a central 'vault' for keys and a 'librarian' to manage them.

More Security Architecture questions