Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityHard

A large enterprise is utilizing a Platform-as-a-Service (PaaS) database offering for its critical customer data. The data is highly sensitive and subject to stringent regulatory requirements for encryption at rest and in transit. The enterprise wants to ensure that they maintain full control over the encryption keys, even though the database itself is managed by the cloud provider. Which key management solution would best meet this requirement?

  1. AHardware Security Module (HSM) as a Service
  2. BCustomer-Managed Keys (CMK)
  3. CCustomer-Provided Keys (CPK)
  4. DProvider-Managed Keys (PMK)
Show answer & explanation

Correct answer: A. Hardware Security Module (HSM) as a Service

HSM as a Service provides dedicated, FIPS-validated hardware for key generation, storage, and cryptographic operations, allowing the customer to retain exclusive control over their encryption keys, even for PaaS services, often with stronger assurances than CMKs.

Why the other options are wrong

  • B. CMK allows the customer to create and manage keys within the provider's Key Management Service (KMS), but the provider still controls the KMS infrastructure itself.
  • C. CPK involves the customer uploading keys to the provider, but the provider often holds a copy or has access, which might not be 'full control'.
  • D. PMK means the cloud provider manages all aspects of the keys, not meeting the 'full control' requirement.

HSM as a Service

A cloud service that provides dedicated, FIPS-validated Hardware Security Modules (HSMs) for customer-exclusive use, offering the highest level of control over encryption keys.

  • Provides dedicated hardware for key generation and storage.
  • Offers cryptographic isolation and tamper resistance.
  • Meets strict compliance requirements for key control.

Memory trick: When it comes to your most precious keys, do you trust the hotel safe (CMK), or do you want your own personal, Fort Knox-level vault (HSM)? For 'full control', you need your own vault.

More Cloud Platform and Infrastructure Security questions