A startup is deploying a new cloud application that stores user profile pictures in an object storage bucket. The security team wants to ensure that data at rest is encrypted and that the encryption keys are managed by the cloud provider with minimal operational overhead. Which encryption option should they choose?
Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all key management, including rotation and storage. This meets the requirement for encryption at rest with minimal operational overhead, as the startup does not need to manage any keys. It is the simplest and most appropriate choice for this scenario.
Why this answer
Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all aspects of key management, including generation, rotation, and storage. This requires no effort from the startup, perfectly aligning with the goal of minimal operational overhead while ensuring data at rest is encrypted.
Exam trap
The trap here is assuming that customer-managed keys in the cloud KMS require no overhead; in reality, they still involve key management tasks, whereas provider-managed keys are fully handled by the provider.