CV0-004 Security Practice Question
A financial services firm stores regulated customer records in an object storage bucket in a public cloud. A compliance auditor requires that every object be encrypted with a customer-managed key so the firm can revoke access instantly and prove key custody, while still allowing the provider to perform envelope encryption for performance. Which configuration meets these requirements?
⚠ Common exam trap
The trap here is conflating encryption at rest with key custody, since provider-managed default encryption encrypts data but leaves the organization unable to revoke access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the bucket to use a customer-managed key stored in the cloud key management service, with automatic key rotation and an audit trail of key usage.
Customer-managed keys held in the cloud key management service satisfy custody and revocation requirements because the organization controls the key lifecycle and can disable the key to cut off decryption instantly. The provider still performs envelope encryption by generating per-object data keys wrapped by the customer-managed key, which keeps performance high and maintains an auditable record of every cryptographic operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable provider-managed default encryption on the bucket using keys the cloud provider generates and rotates automatically.
Why it's wrong here
Provider-managed keys are generated, stored, and rotated entirely by the cloud provider, so the firm cannot demonstrate key custody or revoke access on demand. This fails the auditor's requirement to prove the organization controls the keys. While data is encrypted at rest, the compliance objective of customer-controlled key material and instant revocation is not satisfied by this option.
- ✓
Configure the bucket to use a customer-managed key stored in the cloud key management service, with automatic key rotation and an audit trail of key usage.
Why this is correct
Customer-managed keys in the provider's key management service keep custody with the organization, allow immediate revocation by disabling or deleting the key, and produce an auditable usage trail. The provider still performs envelope encryption, generating a data key per object that is wrapped by the customer-managed key, so performance and server-side functionality are preserved while compliance evidence is generated.
- ✗
Encrypt each object client-side with an application-held symmetric key before uploading, and store the ciphertext in the bucket.
Why it's wrong here
Client-side encryption does give the firm key custody and revocation, but it bypasses the provider's envelope encryption and key management service entirely, contradicting the requirement to let the provider perform envelope encryption. It also pushes key management and rotation burden onto the application, and loses server-side features like range reads and lifecycle policies that depend on readable object metadata.
- ✗
Apply a bucket policy that denies unencrypted uploads and rely on transport layer security to protect objects at rest.
Why it's wrong here
Transport layer security protects data only in transit; it does nothing for data at rest once the object is written to storage. A deny-unencrypted-uploads policy is a useful guardrail but does not itself establish customer key custody or enable cryptographic revocation. This option therefore fails both the encryption-at-rest expectation and the auditor's key control requirement.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.