Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud engineer must ensure that data written to a cloud block storage volume is encrypted at rest using keys the organization controls, while allowing the provider to perform snapshots. The organization wants to avoid re-encrypting data in the application and wants minimal performance impact. Which approach BEST meets these requirements?

⚠ Common exam trap

The trap here is equating provider-managed encryption with customer-controlled keys, when only customer-managed keys in a KMS give the organization lifecycle control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable volume encryption using a customer-managed key stored in a cloud key management service, integrated with the block storage service.

Volume encryption with a customer-managed key in a cloud KMS satisfies both the at-rest encryption mandate and the key-control requirement while remaining transparent to the application. The provider can still snapshot the volume because encryption occurs at the storage layer, and performance impact is minimal. Application-level encryption and provider-managed keys fail one or more stated constraints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable volume encryption using a customer-managed key stored in a cloud key management service, integrated with the block storage service.

    Why this is correct

    Volume-level encryption with a customer-managed key encrypts data at rest transparently to the application, so no application changes are needed. The organization controls the key lifecycle in the cloud KMS, and the provider can still take snapshots because encryption is handled at the storage layer. Performance impact is minimal since encryption is offloaded to the storage infrastructure.

  • ✗

    Store the volume on encrypted hardware and document the provider's physical controls in the risk register.

    Why it's wrong here

    Relying on hardware-level encryption without a customer-managed key does not give the organization control over key material or the ability to revoke access cryptographically. Documenting physical controls addresses audit evidence, not the technical requirement for organization-controlled keys. This approach also does not provide a mechanism to rotate or destroy keys independently.

  • ✗

    Use provider-managed encryption with provider-owned keys and rely on the provider's compliance attestations.

    Why it's wrong here

    Provider-managed keys do not give the organization control over key lifecycle, rotation, or revocation. The requirement explicitly states the organization must control the keys, so this fails the key-control criterion even though it is simple and performant. Provider attestations address provider processes, not the organization's direct control over key material.

  • ✗

    Implement application-level encryption before writing blocks, managing keys in an on-premises HSM.

    Why it's wrong here

    Application-level encryption gives the organization full key control but requires modifying the application and handling key management, which conflicts with the goal of avoiding application re-encryption. It also complicates provider snapshots because the provider stores ciphertext it cannot interpret, potentially affecting snapshot consistency and restore workflows. This adds complexity and performance overhead the scenario seeks to avoid.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.