EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingMedium
A cloud security team is tasked with ensuring the confidentiality and integrity of data stored in a cloud object storage service. They decide to implement client-side encryption, where data is encrypted before being sent to the cloud provider and decrypted after retrieval. What is a key advantage of this approach compared to server-side encryption managed by the cloud provider?
- AReduced computational overhead on the client.
- BEliminates the need for key management by the customer.
- CSimplifies compliance with data residency requirements.
- DProvides end-to-end encryption, ensuring the cloud provider cannot access the plaintext data.
Show answer & explanationAnswer & explanation
Correct answer: D. Provides end-to-end encryption, ensuring the cloud provider cannot access the plaintext data.
Client-side encryption ensures that the data is encrypted before it ever leaves the customer's control and remains encrypted even when stored by the cloud provider. This means the cloud provider never has access to the plaintext data, offering a higher level of confidentiality and control.
Why the other options are wrong
- A. Client-side encryption actually increases computational overhead on the client, as they perform the encryption/decryption.
- B. Client-side encryption places the burden of key management squarely on the customer, as they control the keys.
- C. Client-side encryption does not directly simplify data residency; that depends on where the cloud provider stores the encrypted data.
Client-Side Encryption (Cloud)
Encrypting data on the customer's side before it is transmitted to and stored by the cloud provider, with decryption also occurring client-side.
- Customer retains full control over encryption keys.
- Cloud provider never sees plaintext data.
- Offers strongest confidentiality, but increases client overhead and key management complexity.
Memory trick: Client-side: You hold the key, the cloud only sees the lockbox.