CompTIA SecurityX (CAS-005)Security ArchitectureEasy

A security architect is evaluating a new cloud-native application that processes sensitive financial transactions. The application's design heavily relies on serverless functions and managed databases. To meet compliance requirements, all data at rest and in transit must be encrypted, and cryptographic keys must be managed in a highly secure, auditable, and centralized manner. Which cloud service category is most appropriate for managing these cryptographic keys?

  1. ACompute Service
  2. BKey Management Service (KMS)
  3. CNetworking Service
  4. DStorage Service
Show answer & explanation

Correct answer: B. Key Management Service (KMS)

A Key Management Service (KMS) is specifically designed to create, store, and manage cryptographic keys securely. It provides the necessary controls, auditing capabilities, and integration with other cloud services to meet compliance requirements for sensitive data.

Why the other options are wrong

  • A. Compute services run applications but do not specialize in key management.
  • C. Networking services manage network traffic and connectivity, not cryptographic keys.
  • D. Storage services store data, which can be encrypted, but do not provide the primary key management capabilities.

Key Management Service (KMS)

A cloud service that helps you create and control the encryption keys used to encrypt your data. It provides a centralized, secure, and auditable way to manage the lifecycle of cryptographic keys.

  • Centralized key generation, storage, and usage.
  • Integration with other cloud services for encryption.
  • Provides auditing and access control for keys.

Memory trick: KMS keeps the keys in a central, secure cloud vault.

More Security Architecture questions