Certified Cloud Security Professional (CCSP)Cloud Security OperationsEasy

A financial institution is migrating its highly sensitive customer data to a public cloud environment. Regulatory compliance mandates that all data at rest must be encrypted with customer-managed keys and that the encryption keys themselves must be stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which cloud security operational control is primarily responsible for ensuring these key management requirements are met?

  1. AIdentity and Access Management (IAM) policies.
  2. BCloud Access Security Broker (CASB) implementation.
  3. CKey Management Service (KMS) configuration.
  4. DNetwork Security Group (NSG) rules.
Show answer & explanation

Correct answer: C. Key Management Service (KMS) configuration.

A Key Management Service (KMS) is a cloud-native service designed to create, manage, and protect cryptographic keys, including integration with FIPS 140-2 validated HSMs, directly addressing the requirements for customer-managed keys and secure key storage.

Why the other options are wrong

  • A. IAM policies control who can access resources and perform actions, but they don't manage the keys themselves or their storage in HSMs.
  • B. CASBs focus on enforcing security policies between cloud users and cloud applications, not directly on cryptographic key management.
  • D. NSG rules control network traffic flow and are unrelated to cryptographic key management.

Cloud Key Management Service (KMS)

A cloud-native service that helps you create and control the encryption keys used to protect your data.

  • Manages the lifecycle of cryptographic keys.
  • Integrates with hardware security modules (HSMs) for strong key protection.
  • Supports various encryption scenarios, including data at rest and in transit.

Memory trick: KMS holds the 'Keys' to your cloud kingdom's data.

More Cloud Security Operations questions