Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignHard

A cloud security architect is designing a system that uses serverless functions (FaaS) to process real-time data streams. The organization requires a high degree of assurance that the code executed within these functions has not been tampered with and originates from a trusted source. Additionally, the execution environment itself must be verified for integrity before code execution. Which advanced security concept is most relevant for meeting these requirements?

  1. AConfidential Computing
  2. BData Loss Prevention (DLP)
  3. CAttribute-Based Access Control (ABAC)
  4. DHomomorphic Encryption
Show answer & explanation

Correct answer: A. Confidential Computing

Confidential computing focuses on protecting data in use by performing computation in a hardware-based trusted execution environment (TEE). This ensures that code and data remain confidential and integral even from the cloud provider, directly addressing the need for tamper-proof code execution and verified execution environments.

Why the other options are wrong

  • B. DLP prevents sensitive data exfiltration, not the integrity of code execution or the environment itself.
  • C. ABAC is for granular access control, not for verifying code integrity or execution environments.
  • D. Homomorphic encryption allows computation on encrypted data but doesn't verify the execution environment or code integrity in the manner described.

Confidential Computing

A cloud security concept that protects data in use by performing computation in a hardware-based trusted execution environment (TEE), ensuring data and code confidentiality and integrity.

  • Protects data even from the cloud provider
  • Relies on hardware-level isolation (e.g., Intel SGX, AMD SEV)
  • Addresses concerns about insider threats and supply chain attacks

Memory trick: Confidential computing keeps secrets safe, even from the cloud.

More Cloud Concepts, Architecture and Design questions