CAS-005 · Question #381
A security analyst received the following finding from a cloud security assessment tool: Virtual Machine Data Disk is encrypted with the default encryption key. Because the organization hosts highly s
The correct answer is A. Disk encryption with customer-provided keys E. File-level encryption with customer-provided keys. To meet the regulatory requirement of ensuring that the data is unreadable to the cloud service provider (CSP), the best approach is to use customer-provided keys for encryption. This ensures that only the customer (organization) holds the keys to access the encrypted data, not D
Question
A security analyst received the following finding from a cloud security assessment tool:
Virtual Machine Data Disk is encrypted with the default encryption key. Because the organization hosts highly sensitive data files, regulations dictate it must be encrypted so It is unreadable to the CSP. Which of the following should be implemented to remediate the finding and meet the regulatory requirement? (Choose two.)
Options
- ADisk encryption with customer-provided keys
- BDisk encryption with keys from a third party
- CRow-level encryption with a key escrow
- DFile-level encryption with cloud vendor-provided keys
- EFile-level encryption with customer-provided keys
- FDisk-level encryption with a cross-signed certificate
How the community answered
(65 responses)- A60% (39)
- B3% (2)
- C11% (7)
- D22% (14)
- F5% (3)
Explanation
To meet the regulatory requirement of ensuring that the data is unreadable to the cloud service provider (CSP), the best approach is to use customer-provided keys for encryption. This ensures that only the customer (organization) holds the keys to access the encrypted data, not Disk encryption with customer-provided keys: This ensures the encryption key for the virtual machine’s data disk is managed by the customer, preventing the CSP from having access to the File-level encryption with customer-provided keys: If data needs to be encrypted at the file level, customer-provided keys can be used to ensure that the organization retains control over the encryption and decryption process.
Community Discussion
No community discussion yet for this question.