Certified Cloud Security Professional (CCSP)Cloud Application SecurityEasy
A financial services company is developing a new cloud-native application that will process sensitive customer financial data. Due to regulatory compliance requirements (e.g., GDPR, PCI DSS), they must ensure that all data is encrypted at rest and in transit, and that access to encryption keys is strictly controlled. They also need robust auditing of key usage. Which cloud service category is specifically designed to meet these cryptographic key management and security requirements?
- ACloud Logging and Monitoring Service.
- BCloud Key Management Service (KMS).
- CCloud Storage Service.
- DCloud Identity and Access Management (IAM).
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Key Management Service (KMS).
Cloud Key Management Service (KMS) is a dedicated service for creating, storing, managing, and auditing cryptographic keys. It provides centralized control, integrates with other cloud services for encryption, and offers robust logging of key operations, fulfilling the specified requirements.
Why the other options are wrong
- A. Cloud Logging and Monitoring Service collects logs, including KMS audit logs, but does not manage the keys themselves.
- C. Cloud Storage Service stores encrypted data, but the KMS manages the encryption keys themselves.
- D. Cloud IAM controls who can access resources, including KMS, but does not directly manage cryptographic keys.
Cloud Key Management Service (KMS)
A cloud service that allows users to create, control, and manage cryptographic keys across a wide range of cloud services and applications. It provides a secure and centralized way to manage the lifecycle of encryption keys.
- Centralized key management.
- Secure storage and usage of keys.
- Integration with other cloud services.
- Detailed auditing of key operations.
Memory trick: Think of the KMS as the master locksmith for all your cloud's digital keys.