ISC2 Certified Cloud Security Professional (CCSP) Practice Question
You are designing a key-management architecture for a highly regulated workload that will run on a public IaaS cloud. The policy states that root cryptographic keys must be generated and stored only in tamper-resistant hardware certified to at least FIPS 140-2 Level 3, and that cloud provider personnel must be technically prevented from extracting or replacing those keys. Which option best meets these requirements while still allowing the virtual machines to use the keys for encryption and signing operations?
Use the provider's shared, multi-tenant Key Management Service (KMS) to create customer master keys for the workload.
Enable guest-OS disk encryption and store the encryption passphrases in the cloud provider's secrets-management service.
Attach a virtual Trusted Platform Module (vTPM) to each virtual machine and place the root keys in the vTPM.
Provision a dedicated, customer-managed network Hardware Security Module (HSM) and integrate the virtual machines with it through PKCS#11.
A dedicated, customer-managed network Hardware Security Module (HSM) offers physical, tamper-resistant protection and is independently validated to FIPS 140-2 Level 3. Keys are generated and retained inside the device and are exposed to virtual machines only through cryptographic APIs such as PKCS#11, never in clear text, preventing provider administrators from accessing them.
A virtual TPM attaches to the VM but is ultimately implemented in software under the control of the hypervisor, so a malicious or compromised provider administrator could still access the keys. Software disk-encryption with secrets stored in a generic secrets manager does not satisfy the hardware and FIPS requirements. A shared, multi-tenant key-management service provides logical isolation only and, because the underlying HSMs are managed by the provider, the tenant lacks exclusive control of the hardware, violating the policy mandate.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PKCS#11 and how does it function in cloud environments?
Open an interactive chat with Bash
Why is FIPS 140-2 Level 3 significant for cryptographic hardware?
Open an interactive chat with Bash
What is the difference between a customer-managed HSM and a cloud provider-managed KMS?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .