CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security architect is designing a data protection strategy for a highly sensitive medical imaging application. The application stores patient data in a cloud object storage service. Due to strict HIPAA compliance requirements, all data must be encrypted at rest, and the encryption keys must be managed by the cloud provider's Key Management Service (KMS) with a strong audit trail and integration with IAM for access control. Which server-side encryption method is the most appropriate choice?
- AServer-Side Encryption with KMS-Managed Keys (SSE-KMS)
- BServer-Side Encryption with S3-Managed Keys (SSE-S3)
- CServer-Side Encryption with Customer-Provided Keys (SSE-C)
- DClient-Side Encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with KMS-Managed Keys (SSE-KMS)
SSE-KMS uses the cloud provider's Key Management Service (KMS) to manage encryption keys. This provides a strong audit trail, integrates with IAM for granular access control, and allows for centralized key management, which aligns well with HIPAA compliance for sensitive data.
Why the other options are wrong
- B. SSE-S3 uses keys managed by S3 itself, which offers less control, auditability, and IAM integration compared to KMS.
- C. SSE-C requires the customer to provide and manage their own encryption keys, shifting the burden of key management and auditability to the customer, which might not meet the requirement for provider-managed keys with audit trail.
- D. Client-side encryption means data is encrypted before being sent to the cloud, placing key management entirely on the client, which doesn't meet the requirement for provider-managed keys via KMS.
SSE-KMS (Server-Side Encryption with KMS-Managed Keys)
A server-side encryption method where the cloud provider's Key Management Service (KMS) manages the encryption keys, offering enhanced security features, auditability, and integration with IAM.
- Keys are managed by the cloud provider's KMS.
- Provides an audit trail of key usage.
- Integrates with IAM for granular access control.
Memory trick: KMS Keeps Medical Secrets Safe.