CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a data storage solution for a highly regulated financial institution. The data includes sensitive customer financial records that must be protected against unauthorized access, even by cloud administrators, and remain available under extreme circumstances. The institution has a strict compliance requirement to maintain full control over the encryption keys. Which combination of technologies would BEST meet these requirements?

  1. ADatabase-level encryption with vendor-managed keys and redundant backups.
  2. BVirtual Private Cloud (VPC) with network ACLs and application-level encryption.
  3. CHardware Security Module (HSM) with customer-managed encryption keys (CMEK) and object storage.
  4. DCloud-managed Key Management System (KMS) with client-side encryption.
Show answer & explanation

Correct answer: C. Hardware Security Module (HSM) with customer-managed encryption keys (CMEK) and object storage.

An HSM provides a highly secure, tamper-resistant environment for generating, storing, and managing cryptographic keys, ensuring customer control. Combining this with CMEK (Customer-Managed Encryption Keys) means the institution retains full ownership and control of the keys, even when data is stored in object storage, which offers high availability and durability. This protects against unauthorized access, including from cloud providers.

Why the other options are wrong

  • A. Vendor-managed keys do not meet the strict requirement for the institution to maintain full control over encryption keys.
  • B. VPC and network ACLs provide network segmentation, and application-level encryption is good, but this option does not specify how the encryption keys themselves are protected and fully controlled by the institution, especially against cloud administrators.
  • D. Cloud-managed KMS typically means the cloud provider has some level of control or access to the master keys, which violates the 'full control' requirement.

HSM with CMEK

Hardware Security Modules (HSMs) are physical computing devices that safeguard and manage digital keys, performing cryptographic functions. Customer-Managed Encryption Keys (CMEK) allow customers to use their own encryption keys within cloud services, maintaining full control over the keys.

  • HSMs provide FIPS 140-2 Level 3 (or higher) certified tamper protection.
  • CMEK ensures the customer, not the cloud provider, holds the master key.
  • Prevents cloud administrators from decrypting data without customer's key.
  • Crucial for highly regulated industries requiring strong key governance.

Memory trick: Hardware secures the keys, customer controls the lock.

More Security Architecture questions