C) Encryption for application data is best handled by a storage system or database engine, while storing encryption keys in Vault. This is the most secure approach.
D) The transit secrets engine relieves the burden of proper encryption/decryption from application developers and pushes the burden onto the operators of Vault. This is a huge advantage for dev teams.
B) The transit secrets engine ensures encryption in-transit and at-rest is enforced enterprise wide. This is a critical feature for securing sensitive data.
I like how the transit engine provides a programmatic API that applications can use, as mentioned in Option A. That seems like a really practical feature.
The transit engine sounds like it takes a lot of the complexity of encryption out of the hands of developers, which is really valuable. Option D seems like the most comprehensive answer.
I'm a bit confused about the differences between the transit engine and just storing encryption keys in Vault. Option C seems like it could be a good approach, but I'm not sure.
Arminda
5 days agoVonda
10 days agoAlesia
16 days agoAdelle
21 days agoNoah
26 days agoSarah
1 month agoDanica
1 month agoBecky
1 month agoTom
2 months agoBrittani
2 months agoDaniela
2 months agoGlenna
2 months ago