AWS Certified Security – Specialty — Question 128

A company is developing a highly resilient application to be hosted on multiple Amazon EC2 instances. The application will store highly sensitive user data in
Amazon RDS tables.
The application must:
✑ Include migration to a different AWS Region in the application disaster recovery plan.
✑ Provide a full audit trail of encryption key administration events.
✑ Allow only company administrators to administer keys.
✑ Protect data at rest using application layer encryption.
A Security Engineer is evaluating options for encryption key management.
Why should the Security Engineer choose AWS CloudHSM over AWS KMS for encryption key management in this situation?

Answer options

Correct answer: B

Explanation

The correct answer is B because CloudHSM provides a higher level of control over key management, ensuring that only company administrators can administer the keys, which is crucial for protecting sensitive data. The other options are incorrect because they either exaggerate capabilities (A and C) or present a feature that is not a requirement in this scenario (D).