Courseiva
Cloud Application SecurityeasyMultiple ChoiceObjective-mapped

CCSP Cloud Application Security Practice Question

A cloud application is being designed to handle highly sensitive financial data. The security architect wants to ensure that encryption keys are managed outside the application's memory space. Which service model should they use?

⚠ Common exam trap

Watch out — candidates often confuse CloudHSM (a specific vendor service) with the generic HSM model, or they assume KMS provides the same hardware-level isolation, when in fact KMS often relies on software-based key management that may not guarantee keys are kept outside application memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Hardware Security Module (HSM)

A Hardware Security Module (HSM) is a dedicated hardware appliance that manages encryption keys in a physically and logically isolated environment, entirely separate from the application's memory space. For highly sensitive financial data, an HSM provides FIPS 140-2 Level 3 or higher certification, ensuring keys never leave the device and are protected against memory-scraping attacks. This aligns with the requirement to keep key management outside the application's memory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Hardware Security Module (CloudHSM)

    Why it's wrong here

    CloudHSM is a type of HSM, but the general term HSM is more accurate as the requirement.

  • Key Management Service (KMS)

    Why it's wrong here

    KMS manages keys but may still expose them to the application unless using an HSM backing.

  • Trusted Platform Module (TPM)

    Why it's wrong here

    TPM is used for hardware root of trust on devices, not typically for application key management.

  • Hardware Security Module (HSM)

    Why this is correct

    HSM stores keys in tamper-resistant hardware, isolated from application memory.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.