CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A security architect is evaluating a new cloud-native application that processes sensitive customer PII. The application is designed with a microservices architecture. The architect needs a solution to centrally manage and distribute cryptographic keys for data encryption at rest and in transit across various microservices and cloud services. Which service is best suited for this requirement?
- AHardware Security Module (HSM)
- BSecurity Group
- CKey Management Service (KMS)
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: C. Key Management Service (KMS)
A Key Management Service (KMS) is specifically designed to centrally manage the lifecycle of cryptographic keys, including generation, storage, usage, and rotation, which is essential for a cloud-native application processing sensitive data.
Why the other options are wrong
- A. An HSM is a physical device providing secure key storage and cryptographic operations, but a KMS provides the management layer over potentially multiple HSMs or other key stores in a cloud environment.
- B. Security Groups are virtual firewalls that control inbound and outbound traffic to instances; they are for network access control, not key management.
- D. A VPC is a logically isolated section of a cloud provider's network; it's a networking concept, not a key management service.
Key Management Service (KMS)
A Key Management Service (KMS) is a cloud-based or on-premises service that simplifies the management of cryptographic keys. It allows users to create, store, and control the use of encryption keys across various applications and services.
- Centrally manages cryptographic keys.
- Supports key lifecycle operations (generation, storage, rotation, deletion).
- Integrates with other cloud services for transparent encryption.
- Enhances security by separating key management from application logic.
Memory trick: Keys Managed Securely in the Cloud System.