Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium
A cloud administrator is configuring a new cloud storage bucket for highly sensitive financial records. The organization's policy dictates that data must be encrypted both in transit and at rest, and that the encryption keys must be generated and managed by the cloud provider, but the customer retains the ability to revoke access to the keys at any time. Which key management option best meets these requirements?
- AServer-Side Encryption with Cloud-Managed Keys (SSE-KMS)
- BServer-Side Encryption with Customer-Managed Keys (SSE-CMK)
- CServer-Side Encryption with Cloud-Managed Keys (SSE-C)
- DCustomer-Provided Encryption Keys (CPEK)
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)
SSE-KMS (Key Management Service) allows the cloud provider to manage the encryption keys, but the customer retains control over key usage and revocation policies. This meets the requirement for provider-managed keys with customer control.
Why the other options are wrong
- B. SSE-CMK implies customer-managed keys (CMK) which means the customer creates and manages the key within the cloud provider's KMS, not that the provider generates and manages them entirely.
- C. SSE-C involves the customer providing the encryption key for each object, and the cloud provider uses it for encryption/decryption, but doesn't manage the keys themselves or offer revocation control through a KMS.
- D. CPEK requires the customer to provide and manage their own encryption keys, which contradicts the requirement for provider-managed keys.
Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)
A server-side encryption option where the cloud provider's Key Management Service (KMS) generates and manages the encryption keys, while allowing the customer to control key usage and revocation policies.
- Cloud provider generates and manages keys.
- Customer retains policy control over key usage and revocation.
- Often integrated with other cloud services.
Memory trick: Keys Managed Safely, Customer Retains Control