Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A healthcare provider must ensure that electronic protected health information (ePHI) stored in a public cloud object storage bucket is unreadable to the cloud provider and remains confidential even if the provider's infrastructure is compromised. The security architect wants to use a customer-managed key that never leaves the organization's on-premises hardware security module (HSM). Which approach should the architect implement?

⚠ Common exam trap

Watch out — candidates often confuse provider-side encryption options, such as SSE-C, with true customer-controlled encryption where the key never leaves the customer's premises.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use client-side encryption with a key stored in an on-premises HSM, encrypting data before it is uploaded to the bucket

Client-side encryption with keys held in an on-premises HSM ensures that data is encrypted before it reaches the cloud, so the provider only stores ciphertext and never possesses the key. This architecture preserves confidentiality even if the provider's infrastructure is breached, which is essential for ePHI under strict regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure default encryption on the bucket using a provider-managed key and enable versioning

    Why it's wrong here

    Provider-managed keys are controlled by the cloud provider and can be used to decrypt data at the provider's discretion. This does not prevent the provider from accessing ePHI, nor does it protect against a compromise of the provider's infrastructure. Versioning only protects against accidental deletion or overwrites, not confidentiality.

  • ✗

    Enable provider-side encryption with a customer-provided key (SSE-C) and upload the key with each object request

    Why it's wrong here

    SSE-C requires the customer to send the encryption key with every request, but the cloud provider still handles the encryption and can potentially access the key in memory. It does not keep the key permanently on-premises, and it does not protect against a compromised provider infrastructure that captures the key during processing.

  • ✗

    Implement bucket policies that restrict access to a specific VPC endpoint and enable access logging

    Why it's wrong here

    Bucket policies and VPC endpoints control network access and authorization, but they do not encrypt data at rest. If the provider's infrastructure is compromised, an attacker with sufficient privileges could still read the plaintext objects. Access logging provides audit trails but does not enforce confidentiality.

  • ✓

    Use client-side encryption with a key stored in an on-premises HSM, encrypting data before it is uploaded to the bucket

    Why this is correct

    Client-side encryption performed before upload ensures that the cloud provider only receives ciphertext and never has access to the plaintext or the encryption key. Keeping the key in an on-premises HSM prevents the provider from decrypting data even if its infrastructure is compromised, fully meeting the confidentiality requirement.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.