QuestionQ31

Infrastructure Security

A security engineer must implement a solution to create and control the keys a company uses for cryptographic operations. The security engineer must create symmetric keys whose key material is generated and used in a custom key store backed by an AWS CloudHSM cluster.

The security engineer will use symmetric and asymmetric data key pairs locally within applications. The security engineer must also audit key usage.

How can the security engineer satisfy these requirements?

Explanation

AWS KMS can create symmetric encryption KMS keys in an AWS CloudHSM custom key store; the key material is generated in the associated CloudHSM cluster and cryptographic operations occur in that cluster. AWS CloudTrail records KMS API activity, providing an audit trail of key use. AWS CloudHSM key stores KMS keys in a CloudHSM key store

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!