Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignHard
A global enterprise is evaluating a cloud provider for its new data analytics platform. The platform will process petabytes of sensitive customer data. The enterprise's security policy mandates that all data, regardless of its state, must be protected by encryption. For data that is actively being processed by CPU and residing in volatile memory, which encryption approach is technologically feasible and provides protection against unauthorized access from the underlying cloud infrastructure components (e.g., hypervisor, host OS)?
- AHomomorphic Encryption
- BClient-Side Encryption before upload
- CConfidential Computing with hardware-based TEEs
- DSymmetric Encryption with AES-256
Show answer & explanationAnswer & explanation
Correct answer: C. Confidential Computing with hardware-based TEEs
Confidential Computing, leveraging hardware-based Trusted Execution Environments (TEEs), is designed to protect data *in use* (actively processed by CPU and in memory) from unauthorized access by the underlying cloud infrastructure, including the hypervisor and host OS. This is the most direct and robust solution for this specific requirement.
Why the other options are wrong
- A. Homomorphic Encryption allows computation on encrypted data but is still a nascent technology for general-purpose, high-performance processing and doesn't inherently protect the execution environment itself.
- B. Client-Side Encryption protects data at rest and in transit, but once decrypted for processing, it's vulnerable to the host environment.
- D. Symmetric encryption (AES-256) protects data at rest and in transit, but not typically data in use from a compromised hypervisor.
Confidential Computing
A cloud security technology that protects data in use by performing computation in a hardware-based Trusted Execution Environment (TEE), shielding it from unauthorized access even from the cloud provider.
- Protects data during processing (in use).
- Utilizes hardware-based Trusted Execution Environments (TEEs).
- Shields data from hypervisor, OS, and cloud administrator access.
Memory trick: At Rest, In Transit, In Use: Data needs protection in every phase.