CV0-004 Security Practice Question
A cloud security architect is designing a data protection strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores tenant data in object storage and a managed relational database. Regulators require that each tenant's data be cryptographically isolated so that a key compromise for one tenant cannot expose another tenant's data, and that the organization be able to prove key usage is auditable. Which TWO measures should the architect implement? (Choose two.)
⚠ Common exam trap
The trap here is treating logical isolation, such as row filtering or a single shared key, as equivalent to cryptographic isolation with per-tenant keys and auditable usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a separate customer-managed key per tenant in a managed key management service, with key usage logged to an audit trail.
Per-tenant customer-managed keys in a managed KMS provide cryptographic isolation, and envelope encryption with tenant-specific master keys ensures data keys are wrapped uniquely per tenant. Both approaches rely on KMS audit logging to prove key usage. Shared provider-managed keys, row-level filtering, and a single organization-wide key fail to create per-tenant cryptographic boundaries or auditable key-usage records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable provider-managed encryption at rest on the object storage and database, relying on the provider's default keys.
Why it's wrong here
Provider-managed default keys encrypt all tenants' data under keys the organization does not control, so a compromise or provider-side access could span tenants. There is no per-tenant cryptographic boundary, and the organization cannot produce independent key-usage audit evidence. This fails the isolation and auditability requirements.
- ✗
Store all tenant data in a single database schema and rely on application-level row filtering for isolation.
Why it's wrong here
Row-level filtering in a shared schema provides logical, not cryptographic, isolation. A key compromise or a flaw in the filtering logic could expose all tenants' rows. It does not create separate cryptographic boundaries and cannot produce per-tenant key-usage evidence, so it fails the regulator's requirements.
- ✓
Use a separate customer-managed key per tenant in a managed key management service, with key usage logged to an audit trail.
Why this is correct
A distinct customer-managed key per tenant provides cryptographic isolation, so a compromised key affects only one tenant. Managed KMS services such as AWS KMS, Azure Key Vault, or Cloud KMS log key usage to CloudTrail, Azure Monitor, or Cloud Audit Logs, giving the auditor the required evidence. This directly satisfies both the isolation and auditability requirements.
- ✓
Implement envelope encryption where each tenant has a data key wrapped by a tenant-specific master key stored in the KMS.
Why this is correct
Envelope encryption uses a unique data key per object or tenant, wrapped by a tenant-specific master key in the KMS. The master key never leaves the KMS, so compromise of a wrapped data key does not expose other tenants. KMS audit logs record every wrap and unwrap operation, providing the required proof of key usage and isolation.
- ✗
Encrypt backups with a single organization-wide key and rotate it annually to limit exposure.
Why it's wrong here
A single organization-wide key means one compromise affects every tenant's backups, violating cryptographic isolation. Annual rotation reduces the window but does not create per-tenant boundaries or per-tenant audit evidence. This does not satisfy the requirement that a key compromise for one tenant cannot expose another tenant's data.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.