Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A global enterprise is migrating its sensitive customer data to a public cloud provider. Due to regulatory compliance requirements (e.g., GDPR), the company must ensure that encryption keys for this data are generated and managed in a hardware-secured environment and remain under the company's sole control. Which cloud security service best addresses this specific requirement?

  1. AKey Management Service (KMS)
  2. BIdentity and Access Management (IAM)
  3. CCloud Hardware Security Module (HSM)
  4. DCloud Storage Gateway
Show answer & explanation

Correct answer: C. Cloud Hardware Security Module (HSM)

Cloud HSMs provide dedicated, single-tenant hardware security modules that allow customers to generate and manage their own encryption keys in a FIPS 140-2 Level 3 compliant environment, ensuring exclusive control and meeting stringent compliance needs.

Why the other options are wrong

  • A. KMS provides centralized key management but typically uses shared HSMs or software-based keys, which may not meet the 'sole control' or highest FIPS level requirement.
  • B. IAM controls user access to cloud resources, not the generation and management of encryption keys in hardware.
  • D. Cloud Storage Gateway facilitates data transfer to cloud storage, it does not manage encryption keys.

Cloud Hardware Security Module (HSM)

A dedicated, cloud-based hardware appliance that generates, stores, and protects cryptographic keys within a tamper-resistant environment.

  • Offers the highest level of key security (e.g., FIPS 140-2 Level 3).
  • Provides exclusive control over encryption keys for the customer.
  • Suitable for stringent regulatory compliance and sensitive data.

Memory trick: HSM is like having your own bank vault for keys, under your lock and key alone.

More Cloud Security questions