C) Encryption for application data is best handled by a storage system or database engine, while storing encryption keys in Vault. This is the most secure approach.
D) The transit secrets engine relieves the burden of proper encryption/decryption from application developers and pushes the burden onto the operators of Vault. This is a huge advantage for dev teams.
B) The transit secrets engine ensures encryption in-transit and at-rest is enforced enterprise wide. This is a critical feature for securing sensitive data.
I like how the transit engine provides a programmatic API that applications can use, as mentioned in Option A. That seems like a really practical feature.
The transit engine sounds like it takes a lot of the complexity of encryption out of the hands of developers, which is really valuable. Option D seems like the most comprehensive answer.
I'm a bit confused about the differences between the transit engine and just storing encryption keys in Vault. Option C seems like it could be a good approach, but I'm not sure.
Stanton
3 days agoLisbeth
8 days agoDella
13 days agoFelix
19 days agoTrinidad
24 days agoPatti
29 days agoCoral
1 month agoArminda
2 months agoVonda
2 months agoAlesia
2 months agoAdelle
2 months agoNoah
3 months agoSarah
3 months agoDanica
3 months agoBecky
3 months agoTom
3 months agoBrittani
3 months agoDaniela
4 months agoGlenna
4 months ago