CAS-005 · Question #242
An organization has been using self-managed encryption keys rather than the free keys managed by the cloud provider. The Chief Information Security Officer (CISO) reviews the monthly bill and…
The correct answer is B. Adjust the configuration for cloud provider keys on data that is classified as public. Risk-Based Approach: Using cloud-provider-managed keys for public data is a reasonable risk- based decision. Public data, by definition, is not confidential. Cost Optimization: This directly addresses the CISO's concern about cost, as cloud-provider- managed keys are often free…
Question
An organization has been using self-managed encryption keys rather than the free keys managed by the cloud provider. The Chief Information Security Officer (CISO) reviews the monthly bill and realizes the self-managed keys are more costly than anticipated. Which of the following should the CISO recommend to reduce costs while maintaining a strong security posture?
Options
- AUtilize an on-premises HSM to locally manage keys.
- BAdjust the configuration for cloud provider keys on data that is classified as public.
- CBegin using cloud-managed keys on all new resources deployed in the cloud.
- DExtend the key rotation period to one year so that the cloud provider can use cached keys.
How the community answered
(51 responses)- A4% (2)
- B73% (37)
- C8% (4)
- D16% (8)
Explanation
Risk-Based Approach: Using cloud-provider-managed keys for public data is a reasonable risk- based decision. Public data, by definition, is not confidential. Cost Optimization: This directly addresses the CISO's concern about cost, as cloud-provider- managed keys are often free or significantly cheaper. Security Balance: It maintains a strong security posture for sensitive data by continuing to use customer-managed keys where appropriate, while optimizing costs for less sensitive data.
Community Discussion
No community discussion yet for this question.