Certified Cloud Security Professional (CCSP)Cloud Security OperationsEasy
A financial institution is migrating its highly sensitive customer data to a public cloud environment. Regulatory compliance mandates that all data at rest must be encrypted with customer-managed keys and that the encryption keys themselves must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which cloud security operational control is primarily responsible for ensuring these key management requirements are met?
- AIdentity and Access Management (IAM) policies.
- BCloud Access Security Broker (CASB) implementation.
- CKey Management Service (KMS) configuration.
- DNetwork Security Group (NSG) rules.
Show answer & explanationAnswer & explanation
Correct answer: C. Key Management Service (KMS) configuration.
A Key Management Service (KMS) is a cloud-native service designed to create, manage, and protect cryptographic keys, including integration with FIPS 140-2 validated HSMs, directly addressing the requirements for customer-managed keys and secure key storage.
Why the other options are wrong
- A. IAM policies control who can access resources and perform actions, but they don't manage the keys themselves or their storage in HSMs.
- B. CASBs focus on enforcing security policies between cloud users and cloud applications, not directly on cryptographic key management.
- D. NSG rules control network traffic flow and are unrelated to cryptographic key management.
Cloud Key Management Service (KMS)
A cloud-native service that helps you create and control the encryption keys used to protect your data.
- Manages the lifecycle of cryptographic keys.
- Integrates with hardware security modules (HSMs) for strong key protection.
- Supports various encryption scenarios, including data at rest and in transit.
Memory trick: KMS holds the 'Keys' to your cloud kingdom's data.