CompTIA Cloud+ (CV0-004)SecurityHard

A cloud security architect is designing a key management strategy for highly sensitive data that requires the highest level of security and compliance. The organization needs to maintain complete control over the cryptographic keys and wants to ensure that the cloud provider cannot access the plaintext keys. Which key management approach best meets these requirements?

  1. AClient-Side Encryption
  2. BCustomer Managed Keys (CMK) with Hardware Security Module (HSM)
  3. CCloud Provider Managed Keys
  4. DBring Your Own Key (BYOK)
Show answer & explanation

Correct answer: B. Customer Managed Keys (CMK) with Hardware Security Module (HSM)

Customer Managed Keys (CMK) with an underlying Hardware Security Module (HSM) provides the strongest control, as the keys are generated, stored, and used within a FIPS 140-2 Level 3 compliant hardware module, making it impossible for the cloud provider to extract them. While BYOK imports customer-generated keys, they might still be managed by the cloud provider's KMS, potentially exposing them to the provider in certain scenarios, whereas HSM-backed CMKs ensure the keys never leave the hardware module.

Why the other options are wrong

  • A. Client-side encryption performs encryption before data leaves the client, giving full control over keys, but the question asks about a 'key management strategy' within the cloud provider's services, and often this is combined with CMK/HSM for key storage.
  • C. Cloud Provider Managed Keys give the least control to the customer, as the provider fully manages the keys.
  • D. BYOK allows importing customer-generated keys, but their subsequent management might still occur within the cloud provider's KMS, potentially exposing them to the provider's control mechanisms, unlike HSM-backed keys that never leave the hardware.

Customer Managed Keys (CMK) with HSM

CMK with HSM involves customers generating and managing their cryptographic keys within a dedicated Hardware Security Module (HSM) provided by the cloud vendor, ensuring the highest level of security and control over key lifecycle.

  • Keys are generated and stored in a tamper-resistant HSM.
  • Cloud provider cannot access or extract plaintext keys.
  • Meets strict compliance requirements (e.g., FIPS 140-2 Level 3).

Memory trick: HSM-backed CMKs give ultimate key control, never exposed.

More Security questions