Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud administrator is configuring a new object storage bucket that will hold internal project files. The organization's policy states that data must be encrypted at rest, but the team wants the cloud provider to handle all key management with no additional operational overhead. Which configuration meets this policy with the least administrative effort?

⚠ Common exam trap

The trap here is conflating access control with encryption, when bucket policies restrict who can read data but leave the stored bytes unencrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the bucket's default server-side encryption using provider-managed keys.

Server-side encryption with provider-managed keys encrypts objects at rest automatically and delegates key lifecycle to the cloud provider. It requires no customer key handling, no application changes, and no extra infrastructure, so it satisfies the encryption-at-rest policy with the least administrative effort. Client-side encryption and third-party gateways add operational burden, while access policies alone do not encrypt data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a third-party encryption gateway that proxies all uploads and encrypts objects before they reach the bucket.

    Why it's wrong here

    A third-party gateway can provide encryption, but it adds a new component to deploy, license, monitor, and maintain. It introduces another failure point and requires integration work, which contradicts the low-overhead objective. Native server-side encryption already meets the policy without adding external infrastructure, so the gateway is unnecessary here.

  • ✓

    Enable the bucket's default server-side encryption using provider-managed keys.

    Why this is correct

    Server-side encryption with provider-managed keys encrypts objects at rest automatically and the provider handles key creation, storage, and rotation. It requires no customer key infrastructure or application changes, so it meets the policy of encryption at rest with minimal operational overhead. This is the standard baseline for object storage and is usually enabled by default in modern cloud platforms.

  • ✗

    Store the files in a bucket without encryption but restrict access using bucket policies.

    Why it's wrong here

    Access controls limit who can read data but do not encrypt it at rest. If the underlying storage media were exposed, the data would be readable in plaintext. This violates the organization's explicit policy that data must be encrypted at rest, regardless of how tightly access is restricted through policies or identity controls.

  • ✗

    Encrypt each file on the client side before uploading it to the bucket.

    Why it's wrong here

    Client-side encryption does satisfy encryption at rest, but it shifts key management, tooling, and application changes onto the team. Users must handle key storage, rotation, and distribution, and any lost key means permanent data loss. This creates significant operational overhead, which directly conflicts with the stated goal of minimal administrative effort.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.