CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is tasked with ensuring that sensitive customer data stored in a cloud database remains encrypted even when the cloud provider's administrators might have access to the underlying infrastructure. The solution must allow the customer to retain full control over the encryption keys, preventing the cloud provider from decrypting the data without explicit customer action. Which encryption key management approach should the architect recommend?

  1. ACustomer Managed Keys (CMK) with an External Key Store
  2. BCloud Provider Managed Keys
  3. CCustomer Provided Keys (CPK)
  4. DBring Your Own Key (BYOK) with Cloud HSM
Show answer & explanation

Correct answer: D. Bring Your Own Key (BYOK) with Cloud HSM

Bring Your Own Key (BYOK) combined with a Cloud Hardware Security Module (HSM) allows the customer to generate and store their encryption keys within a dedicated, tamper-resistant hardware module that only they control. Even if the cloud provider has access to the cloud infrastructure, they cannot access the keys within the customer's HSM, ensuring the data remains undecryptable by the provider.

Why the other options are wrong

  • A. Customer Managed Keys (CMK) with an External Key Store (like a KMS outside the cloud) offers good control, but BYOK with Cloud HSM provides stronger assurance against provider access due to the dedicated hardware isolation.
  • B. Cloud Provider Managed Keys give the cloud provider full control over key lifecycle and access, directly contradicting the requirement for customer control.
  • C. Customer Provided Keys (CPK) means the customer provides the key, but the cloud provider typically holds and manages it thereafter, which doesn't guarantee the provider can't access it.

Bring Your Own Key (BYOK) with Cloud HSM

A cloud encryption key management strategy where customers generate their own keys on-premises and securely transfer them to a dedicated Hardware Security Module (HSM) managed by the cloud provider but controlled by the customer.

  • Customer retains full control over key generation and lifecycle.
  • Keys are stored in a tamper-resistant hardware module (HSM) in the cloud.
  • Prevents cloud provider from accessing unencrypted keys or customer data without explicit customer action.

Memory trick: BYOK + HSM = Your Keys, Your Rules, Hardware Secure.

More Security Architecture questions