CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security engineer is tasked with implementing a key management solution for an application that processes highly sensitive customer data. The solution must ensure that encryption keys are generated, stored, and used within a FIPS 140-2 Level 3 compliant hardware module, and that the cloud provider has no access to the plaintext keys. Which key management service model should the engineer recommend?

  1. ACustomer Provided Keys (CPK)
  2. BShared Key Management
  3. CCustomer Managed Keys (CMK) with HSM
  4. DCloud Provider Managed Keys
Show answer & explanation

Correct answer: C. Customer Managed Keys (CMK) with HSM

Customer Managed Keys (CMK) with an HSM provides the highest level of control and security for encryption keys. It ensures that keys are generated, stored, and used within a FIPS 140-2 Level 3 compliant hardware security module (HSM) that is dedicated to the customer, preventing the cloud provider from accessing the plaintext keys.

Why the other options are wrong

  • A. Customer Provided Keys involve the customer bringing keys, but doesn't specify HSM protection or cloud provider isolation for key operations.
  • B. Shared Key Management is a generic term and doesn't specify the level of control or hardware compliance required.
  • D. Cloud Provider Managed Keys give the cloud provider control over key lifecycle, failing the 'no cloud provider access' requirement.

Customer Managed Keys (CMK) with HSM

A key management model where customers generate, store, and manage their encryption keys within a dedicated Hardware Security Module (HSM) provided by the cloud vendor, ensuring high levels of security and regulatory compliance.

  • Keys are isolated within a FIPS 140-2 Level 3 compliant HSM.
  • Cloud provider cannot access plaintext keys.
  • Customer retains full control over key lifecycle.
  • Often used for highly regulated industries and sensitive data.

Memory trick: CMK with HSM: Customer's Keys, Hardware's Security, My Control.

More Security questions