CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is designing a new microservices platform that will host sensitive customer data. The platform requires that all data at rest be encrypted, and the encryption keys must be rotated regularly (e.g., annually) and managed centrally. Furthermore, the system must ensure that if a key is compromised, the impact is limited to the data encrypted by that specific key generation. Which key management practice would BEST achieve these goals?

  1. AStoring encryption keys directly within each microservice's configuration files for local access.
  2. BUsing a single master encryption key for all data and rotating it annually.
  3. CEmploying envelope encryption with unique data encryption keys (DEKs) for each data object, protected by Key Encryption Keys (KEKs) that are rotated.
  4. DImplementing a Key Derivation Function (KDF) to generate unique keys per microservice.
Show answer & explanation

Correct answer: C. Employing envelope encryption with unique data encryption keys (DEKs) for each data object, protected by Key Encryption Keys (KEKs) that are rotated.

Envelope encryption is the most effective practice for achieving the stated goals. It involves encrypting each data object with a unique Data Encryption Key (DEK), and then encrypting these DEKs with a smaller set of Key Encryption Keys (KEKs). The KEKs are then protected by a Master Key (often in an HSM). This design allows for independent rotation of KEKs and DEKs, and if a KEK is compromised, only the DEKs encrypted by that KEK are at risk, limiting the blast radius. If a DEK is compromised, only the specific data object it encrypted is affected. This provides fine-grained control, robust key rotation, and limited impact from key compromise.

Why the other options are wrong

  • A. Storing keys in configuration files is highly insecure, makes key rotation difficult, and fails to provide tamper resistance or limited blast radius, directly contradicting security best practices.
  • B. Using a single master key for all data creates a single point of failure and a massive blast radius if compromised, contradicting the goal of limiting impact.
  • D. While KDFs can generate unique keys, simply generating unique keys per microservice doesn't address the fine-grained 'per data object' encryption, robust rotation, or hierarchical protection provided by envelope encryption.

Envelope Encryption

Envelope encryption is a cryptographic technique where data is encrypted with a unique Data Encryption Key (DEK), and then the DEK itself is encrypted (wrapped) by a different Key Encryption Key (KEK).

  • Uses hierarchical key structure (DEK, KEK, Master Key).
  • Limits the blast radius of a compromised key.
  • Enables efficient key rotation for KEKs without re-encrypting all data.
  • Commonly used in cloud services for data at rest encryption.

Memory trick: Envelopes Limit Key Compromise Impact

More Security Engineering questions