Certified Cloud Security Professional (CCSP)Cloud Application SecurityHard

A cloud application processes sensitive customer data and must comply with GDPR. The development team is using serverless functions and object storage. They need to ensure that data in object storage is encrypted at rest and that the encryption keys are managed separately from the data itself, with strong access controls. Which of the following approaches best addresses this requirement?

  1. AServer-side encryption with customer-provided keys (SSE-C) where the application provides the key for each object.
  2. BServer-side encryption with customer-managed keys (SSE-KMS) using a dedicated Key Management Service (KMS).
  3. CServer-side encryption with platform-managed keys (SSE-S3/SSE-C/SSE-KMS) for object storage.
  4. DClient-side encryption using a customer-managed key stored in an application configuration file.
Show answer & explanation

Correct answer: B. Server-side encryption with customer-managed keys (SSE-KMS) using a dedicated Key Management Service (KMS).

Server-side encryption with customer-managed keys (SSE-KMS) using a dedicated Key Management Service (KMS) provides the strongest control over encryption keys. It ensures keys are managed separately from the data, allows for fine-grained access control, and typically includes auditing capabilities, which aligns with GDPR's requirements for data protection and accountability.

Why the other options are wrong

  • A. Customer-provided keys (SSE-C) require the application to manage and provide keys, increasing the risk of key exposure and operational complexity.
  • C. Platform-managed keys (SSE-S3) are easier but offer less control over key lifecycle and access compared to customer-managed keys, which is often preferred for GDPR compliance.
  • D. Storing keys in configuration files is insecure and doesn't provide the robust key management or auditing required for sensitive data.

Server-Side Encryption with Customer-Managed Keys (SSE-KMS)

A method where data is encrypted by the cloud provider's service, but the encryption keys are generated and managed by the customer using a dedicated Key Management Service.

  • Keys are separate from data.
  • Customer retains control over key lifecycle.
  • KMS provides auditing and access control for keys.

Memory trick: KMS gives customers total Key Management for Secure data.

More Cloud Application Security questions