CompTIA Cloud+ (CV0-004)SecurityHard
A global financial institution is expanding its cloud presence. As part of its compliance obligations, it must ensure that all data stored in the cloud is protected with encryption, both in transit and at rest. Furthermore, the cryptographic keys used for this encryption must be securely managed, rotated regularly, and have a clear audit trail of their usage. Which component of the cloud security framework is primarily responsible for generating, storing, and managing these encryption keys?
- AKey Management Service (KMS)
- BIdentity and Access Management (IAM)
- CNetwork Security Groups (NSG)
- DCloud Security Posture Management (CSPM)
Show answer & explanationAnswer & explanation
Correct answer: A. Key Management Service (KMS)
A Key Management Service (KMS) is a dedicated cloud service specifically designed for generating, storing, managing, and controlling access to cryptographic keys, including features like key rotation and audit trails, which are critical for compliance.
Why the other options are wrong
- B. IAM manages user identities and permissions but does not directly handle the generation or storage of cryptographic keys.
- C. Network Security Groups (NSG) control network traffic flow, acting as virtual firewalls, and are unrelated to key management.
- D. CSPM focuses on identifying misconfigurations and compliance risks across the cloud environment, not on the direct management of encryption keys.
Key Management Service (KMS)
A cloud service that provides centralized control over the lifecycle of cryptographic keys, including generation, storage, rotation, and access management.
- Manages symmetric and asymmetric keys.
- Integrates with other cloud services for encryption.
- Provides audit trails for key usage.
Memory trick: IAM Knights Guard Many Secret Keys.