Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A company is migrating its on-premises data warehouse to a public cloud provider. During the planning phase, the security team identifies a critical requirement: all data in transit between the on-premises network and the cloud data warehouse, as well as data at rest within the cloud storage, must be encrypted using FIPS 140-2 validated modules. Which cloud security control is most directly responsible for ensuring data at rest encryption meets this standard?

  1. AKey Management Service (KMS)
  2. BVirtual Private Cloud (VPC)
  3. CCloud Access Security Broker (CASB)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: A. Key Management Service (KMS)

A Key Management Service (KMS) is specifically designed to manage cryptographic keys, including their generation, storage, and lifecycle. Cloud providers' KMS offerings often integrate with their storage services to encrypt data at rest and can be configured to use FIPS 140-2 validated hardware security modules (HSMs).

Why the other options are wrong

  • B. A VPC provides network isolation within the cloud, not direct control over encryption key management for data at rest.
  • C. A CASB focuses on monitoring and enforcing security policies for cloud application usage, not directly on managing encryption keys for data at rest.
  • D. A SIEM aggregates and analyzes security logs, but does not directly manage or enforce encryption standards for data at rest.

Key Management Service (KMS)

A cloud service that helps you create and control the encryption keys used to encrypt your data.

  • Centralizes key generation, storage, and access control.
  • Integrates with other cloud services for data encryption.
  • Often supports FIPS 140-2 validated hardware for key protection.

Memory trick: KMS: Keys Masterfully Secured for your data.

More Cloud Security questions