CompTIA SecurityX (CAS-005)Security ArchitectureEasy
A security architect is designing a new cloud-native application that will handle sensitive customer payment information. The application needs to ensure that all data at rest in the database is encrypted, and that the encryption keys are managed securely and rotated regularly. The organization wants to leverage cloud-native services for key management to reduce operational overhead while maintaining control over key access policies. Which cloud service should the architect integrate?
- AIdentity and Access Management (IAM)
- BVirtual Private Cloud (VPC)
- CCloud Object Storage
- DKey Management Service (KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. Key Management Service (KMS)
A Key Management Service (KMS) is a cloud-native service specifically designed to create, store, manage, and control access to encryption keys. It supports key rotation and integrates with other cloud services to encrypt data at rest, directly fulfilling the requirements.
Why the other options are wrong
- A. IAM manages user and service permissions, which is related to KMS access but is not the key management service itself.
- B. VPC provides a logically isolated section of the cloud for network resources, not for encryption key management.
- C. Cloud Object Storage is for storing data, not for managing encryption keys.
Key Management Service (KMS)
A cloud-native service that enables the creation, control, and management of cryptographic keys across various cloud services and applications.
- Provides a centralized solution for key lifecycle management.
- Integrates with other cloud services for data encryption at rest and in transit.
- Supports key rotation, access control, and auditing of key usage.
Memory trick: KMS: Keys Managed Securely.