CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security architect is designing a data protection strategy for sensitive customer data stored in an object storage service. The requirement is that all data uploaded to the bucket must be encrypted at rest, and the encryption keys must be managed by the cloud provider, but specific to the customer's account, not shared with other customers. Which server-side encryption method should be chosen?

  1. AClient-Side Encryption
  2. BServer-Side Encryption with KMS Managed Keys (SSE-KMS)
  3. CServer-Side Encryption with Customer-Provided Keys (SSE-C)
  4. DServer-Side Encryption with S3 Managed Keys (SSE-S3)
Show answer & explanation

Correct answer: B. Server-Side Encryption with KMS Managed Keys (SSE-KMS)

Server-Side Encryption with KMS Managed Keys (SSE-KMS) uses keys managed by a Key Management Service (KMS) within the cloud provider. While the cloud provider manages the KMS infrastructure, the encryption keys used are specific to the customer's account and are generated and controlled within the KMS, meeting the requirement for provider-managed but customer-specific keys.

Why the other options are wrong

  • A. Client-Side Encryption encrypts data before it leaves the client, not a server-side encryption method managed by the cloud provider.
  • C. SSE-C requires the customer to provide and manage the encryption keys, not the cloud provider.
  • D. SSE-S3 uses keys fully managed by the object storage service, which are not specific to the customer's account and may be shared across the service.

SSE-KMS

Server-Side Encryption with KMS (Key Management Service) Managed Keys encrypts data at rest using keys stored and managed within the cloud provider's KMS, specific to the customer's account.

  • Keys are unique to the customer account.
  • KMS provides auditing and key rotation.
  • Cloud provider manages the KMS infrastructure.
  • Offers more control than SSE-S3, less than SSE-C.

Memory trick: KMS: 'K'eys 'M'anaged by 'S'ervice, specific to 'K'ustomer.

More Security questions