Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy
A cloud application needs to retrieve sensitive configuration data, such as database connection strings and API keys, from a central repository. This data must be encrypted at rest, accessible only by authorized application instances, and rotated automatically without requiring application downtime. Which of the following cloud application security technologies is specifically designed to manage these requirements?
- AObject Storage with Server-Side Encryption (SSE-S3).
- BIdentity and Access Management (IAM) roles and policies.
- CSecrets Management Service (e.g., AWS Secrets Manager, Azure Key Vault).
- DKey Management Service (KMS) for cryptographic operations.
Show answer & explanationAnswer & explanation
Correct answer: C. Secrets Management Service (e.g., AWS Secrets Manager, Azure Key Vault).
A Secrets Management Service is purpose-built to securely store, retrieve, and automatically rotate sensitive data (secrets) like database credentials and API keys. It integrates with IAM for access control and often leverages KMS for encryption, meeting all specified requirements.
Why the other options are wrong
- A. Object storage can store encrypted data, but it's not designed for the dynamic retrieval and automatic rotation of application secrets.
- B. IAM defines who can access what, but it doesn't provide the secure storage, encryption, or rotation capabilities for the secrets themselves.
- D. KMS manages encryption keys, which is a component used by secrets management, but KMS itself doesn't store and rotate application secrets.
Secrets Management Service
A cloud service designed to securely store, manage, and retrieve sensitive application credentials and configuration data (secrets), often including automatic rotation.
- Centralized storage for secrets.
- Integrates with IAM for access control.
- Supports automatic key/secret rotation.
Memory trick: Secrets Manager keeps app secrets safe and sound.