Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium
A large enterprise is migrating its legacy data warehouse to a public cloud. The data warehouse contains petabytes of historical customer transaction data. The enterprise's compliance team requires that all data, regardless of its age or access frequency, must be encrypted with customer-managed keys and that the encryption keys must be stored in a FIPS 140-2 Level 3 certified hardware security module (HSM). Which cloud security challenge does this requirement primarily address?
- AData Locality
- BData Residency
- CKey Management
- DCloud Provider Lock-in
Show answer & explanationAnswer & explanation
Correct answer: C. Key Management
The requirement for customer-managed encryption keys and FIPS 140-2 Level 3 certified HSMs directly pertains to the challenge of securely managing cryptographic keys, which is a critical aspect of protecting sensitive data in the cloud.
Why the other options are wrong
- A. Data locality refers to data being close to processing for performance, not key management.
- B. Data residency relates to the physical location of data, not key management.
- D. Cloud provider lock-in relates to portability, not the secure handling of encryption keys.
Key Management
The process of managing cryptographic keys throughout their lifecycle, including generation, storage, distribution, usage, and revocation.
- Crucial for data encryption effectiveness
- Can be complex in cloud environments
- Often involves HSMs for enhanced security
Memory trick: Key challenges in the cloud require careful handling.