Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A global enterprise is migrating its sensitive customer data to a public cloud provider. Due to regulatory compliance requirements (e.g., GDPR), the company must ensure that encryption keys for this data are generated and managed in a hardware-secured environment and remain under the company's sole control. Which cloud security service best addresses this specific requirement?
- AKey Management Service (KMS)
- BIdentity and Access Management (IAM)
- CCloud Hardware Security Module (HSM)
- DCloud Storage Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Hardware Security Module (HSM)
Cloud HSMs provide dedicated, single-tenant hardware security modules that allow customers to generate and manage their own encryption keys in a FIPS 140-2 Level 3 compliant environment, ensuring exclusive control and meeting stringent compliance needs.
Why the other options are wrong
- A. KMS provides centralized key management but typically uses shared HSMs or software-based keys, which may not meet the 'sole control' or highest FIPS level requirement.
- B. IAM controls user access to cloud resources, not the generation and management of encryption keys in hardware.
- D. Cloud Storage Gateway facilitates data transfer to cloud storage, it does not manage encryption keys.
Cloud Hardware Security Module (HSM)
A dedicated, cloud-based hardware appliance that generates, stores, and protects cryptographic keys within a tamper-resistant environment.
- Offers the highest level of key security (e.g., FIPS 140-2 Level 3).
- Provides exclusive control over encryption keys for the customer.
- Suitable for stringent regulatory compliance and sensitive data.
Memory trick: HSM is like having your own bank vault for keys, under your lock and key alone.