問題文
An application must store sensitive fields in its own relational database in encrypted form. The team does not want to write key management code and does not want the application process to ever hold the encryption key. Which arrangement does the encryption service engine provide?
選択肢
- Vault connects to the application's database and encrypts the sensitive columns in place, so the application code does not have to change at all.
- The application sends the field to Vault, stores the returned ciphertext in its own database, and sends that ciphertext back to Vault when it needs the value.
- Vault issues a short-lived data encryption key to the application on each write, which the application uses locally and then discards, so no ciphertext ever leaves the application.
- The application sends the field to Vault, and Vault stores the ciphertext so the application only has to keep the key name and the record identifier.