CompTIA Cloud+ (CV0-004)SecurityMedium
A global enterprise is migrating its sensitive customer data to a multi-cloud environment. Due to stringent regulatory requirements in various jurisdictions, the company must ensure that encryption keys for data stored in a specific region are generated, managed, and stored exclusively within that geographic region. Which key management solution would best meet this data sovereignty and compliance requirement?
- AHardware Security Modules (HSMs) as a Service with regional isolation
- BServer-Side Encryption with Customer-Provided Keys (SSE-C)
- CCloud Provider's Default Key Management Service (KMS)
- DClient-Side Encryption with self-managed keys
Show answer & explanationAnswer & explanation
Correct answer: A. Hardware Security Modules (HSMs) as a Service with regional isolation
HSMs as a Service, especially those offering regional isolation, provide the highest level of assurance for key generation, storage, and management within a specific geographic boundary, directly addressing data sovereignty and compliance needs.
Why the other options are wrong
- B. SSE-C involves the customer providing keys to the cloud service for encryption, but the key management itself (generation, storage, lifecycle) is still largely up to the customer and doesn't guarantee regional hardware isolation for the key infrastructure.
- C. Cloud Provider's Default KMS might not offer explicit guarantees for key generation and storage within a specific, isolated geographic region at the hardware level, as required for strict data sovereignty.
- D. Client-side encryption with self-managed keys places the burden of key management entirely on the client, which can be complex and may not inherently guarantee regional key storage without significant custom effort.
HSM as a Service for Regional Keys
A cloud service offering dedicated, tamper-resistant hardware security modules (HSMs) for cryptographic operations and key storage, often with guarantees for physical location and isolation.
- Provides highest assurance for key security and sovereignty.
- Keys generated and stored in FIPS 140-2 Level 3+ validated hardware.
- Helps meet strict regulatory compliance for key management.
Memory trick: HSMs Hold High Sovereignty Standards Securely.