Courseiva
Cloud Data SecuritymediumMultiple SelectObjective-mapped

CCSP Cloud Data Security Practice Question

A cloud architect is designing key management for a multi-tenant SaaS application. The architect must ensure that each customer's encryption keys are isolated and that the cloud provider cannot access the keys. Which TWO key management strategies meet these requirements? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Client-side encryption

Client-side encryption ensures data is encrypted before it reaches the cloud, so the cloud provider never sees plaintext or keys. Hold Your Own Key (HYOK) keeps the key on-premises in an HSM, never exposing it to the cloud. Both give the customer exclusive control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Client-side encryption

    Why this is correct

    Data is encrypted before upload; cloud never sees keys.

  • Customer-managed encryption keys (CMEK)

    Why it's wrong here

    Keys are managed by customer but stored in cloud KMS; provider may have access under some conditions.

  • Hold your own key (HYOK)

    Why this is correct

    Key remains on-premises HSM; cloud provider cannot access it.

  • Bring your own key (BYOK)

    Why it's wrong here

    Key is imported into cloud KMS; provider may have access.

  • Cloud provider default server-side encryption

    Why it's wrong here

    Cloud provider manages keys; provider can access them.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.