CompTIA SecurityX (CAS-005)Security EngineeringHard
A security architect is developing a strategy for long-term data archival that must maintain confidentiality for several decades, even against adversaries with significant computational power. The architect is particularly concerned about the future threat of quantum computers compromising currently strong asymmetric encryption algorithms. Which key management strategy is MOST critical to implement to mitigate this specific long-term threat to the archived data?
- AImplementing Post-Quantum Cryptography (PQC) for key exchange and digital signatures.
- BRegularly rotating symmetric encryption keys (e.g., AES-256) every 90 days.
- CUsing a robust Hardware Security Module (HSM) for all key generation and storage.
- DEmploying an envelope encryption scheme with a cloud Key Management Service (KMS).
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing Post-Quantum Cryptography (PQC) for key exchange and digital signatures.
The core concern is the 'future threat of quantum computers compromising currently strong asymmetric encryption algorithms' for 'long-term data archival'. Post-Quantum Cryptography (PQC) is specifically designed to withstand attacks from quantum computers, making it the most critical strategy for ensuring the long-term confidentiality of data against this particular threat.
Why the other options are wrong
- B. Rotating symmetric keys is good practice but doesn't address the quantum threat to the asymmetric algorithms used for initial key exchange or digital signatures, which are typically the weakest link.
- C. HSMs provide secure storage and operations for keys but don't change the underlying cryptographic algorithms. If the algorithm itself is vulnerable to quantum attacks, the HSM won't protect it.
- D. Envelope encryption with a KMS is an excellent key management practice for data at rest, but it doesn't inherently solve the problem of quantum vulnerability in the underlying public-key cryptography used for establishing the KEKs or securing the KMS itself.
Post-Quantum Cryptography (PQC) for Key Management
The use of cryptographic algorithms designed to be secure against attacks by quantum computers, specifically applied to key exchange and digital signatures to protect long-term data confidentiality.
- Mitigates the threat of quantum computers breaking current public-key crypto
- Essential for 'harvest now, decrypt later' scenarios
- Focuses on securing key establishment and authentication in a quantum future
Memory trick: PQC protects keys from Quantum Computers.