Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM C1000-172 Exam - Topic 2 Question 37 Discussion

An organization needs to encrypt IBM Cloud Kubernetes Service secrets and the etcd store with their own root keys. The encryption should occur on FIPS 140-2 Level 4-certified hardware. Which service should this organization use?
A) IBM Cloud Hyper Protect Crypto Services
B) IBM Cloud Secrets Manager
C) IBM Cloud Key Protect
D) IBM Cloud Managed Encryption Services

IBM C1000-172 Exam - Topic 2 Question 37 Discussion

Actual exam question for IBM's C1000-172 exam
Question #: 37
Topic #: 2
[All C1000-172 Questions]

An organization needs to encrypt IBM Cloud Kubernetes Service secrets and the etcd store with their own root keys. The encryption should occur on FIPS 140-2 Level 4-certified hardware. Which service should this organization use?

Show Suggested Answer Hide Answer
Suggested Answer: A

IBM Cloud Hyper Protect Crypto Services is the correct service to use for encrypting IBM Cloud Kubernetes Service secrets and the etcd store with the organization's own root keys on FIPS 140-2 Level 4-certified hardware.

IBM Cloud Hyper Protect Crypto Services: This service provides a highly secure key management system and supports encryption operations using FIPS 140-2 Level 4-certified hardware. It ensures that the keys used to encrypt data never leave the secure boundary of the Hardware Security Module (HSM), which meets the highest level of security certification (Level 4).

Use Case Suitability: For organizations needing to meet stringent regulatory and compliance requirements (such as those demanding FIPS 140-2 Level 4 certification), Hyper Protect Crypto Services offers the necessary security controls to protect Kubernetes secrets and other sensitive data.

Reference from IBM Cloud Professional Architect Materials:

The IBM documentation on Hyper Protect Crypto Services confirms that it uses FIPS 140-2 Level 4-certified hardware, making it the correct choice for this requirement.

Other options are incorrect:

B . IBM Cloud Secrets Manager and C. IBM Cloud Key Protect do not utilize FIPS 140-2 Level 4-certified hardware.

D . IBM Cloud Managed Encryption Services is not a specific service related to the required encryption hardware.


Contribute your Thoughts:

0/2000 characters
Rasheeda
2 days ago
I thought B) IBM Cloud Secrets Manager would be enough for this.
upvoted 0 times
...
Rory
7 days ago
Totally agree, it’s designed for FIPS compliance.
upvoted 0 times
...
Glory
12 days ago
A) IBM Cloud Hyper Protect Crypto Services is the right choice!
upvoted 0 times
...
Maddie
17 days ago
I’m a bit confused about the differences between these services. I thought IBM Cloud Secrets Manager was for managing secrets, not necessarily for encryption at that level.
upvoted 0 times
...
Jacquline
22 days ago
I feel like I've seen a similar question before, and it was focused on hardware security modules. That makes me lean towards A as well.
upvoted 0 times
...
Rocco
28 days ago
I'm not entirely sure, but I remember something about IBM Cloud Key Protect being used for managing encryption keys. Could it be relevant here?
upvoted 0 times
...
Dottie
1 month ago
I think the answer might be A) IBM Cloud Hyper Protect Crypto Services since it specifically mentions FIPS 140-2 Level 4 certification.
upvoted 0 times
...

Save Cancel