CCSP Cloud Application Security Practice Question
A cloud operations team is deploying a web application that stores configuration files and application logs in an object storage bucket. The security policy requires that data be encrypted at rest, and the team wants the cloud provider to manage the encryption keys with minimal operational overhead. The bucket must remain accessible to the application without code changes. Which approach should the team use?
⚠ Common exam trap
The trap here is assuming that encryption at rest always requires customer-managed keys or client-side code, when provider-managed server-side encryption already satisfies the policy with less overhead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable server-side encryption with provider-managed keys on the bucket, which automatically encrypts objects at rest.
Provider-managed server-side encryption is the lowest-overhead way to meet an encryption-at-rest requirement because the cloud service handles key storage, rotation, and cryptographic operations automatically. The application's read and write operations remain unchanged, so no code modifications are needed. This satisfies both the security policy and the operational constraints described by the team.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use server-side encryption with customer-provided keys, supplying the key in each request so the provider does not store it.
Why it's wrong here
Customer-provided keys require the application to include the key with every request and the team to manage key material securely, adding operational overhead and potential for errors. It also typically requires code changes to pass the key. This does not meet the minimal-overhead goal and is unnecessary when provider-managed keys satisfy the encryption-at-rest policy.
- ✗
Rely on transport layer security for data in transit and document that encryption at rest is not required for configuration files.
Why it's wrong here
TLS protects data in transit but does not encrypt objects at rest in the bucket. The security policy explicitly requires encryption at rest, so relying on transport security alone leaves stored data unprotected and violates the policy. This approach also ignores the risk of unauthorized access to the storage medium or backups.
- ✗
Implement client-side encryption in the application so that objects are encrypted before upload, using keys stored in the application configuration.
Why it's wrong here
Client-side encryption requires application code changes to encrypt and decrypt objects and places key management burden on the team, including secure storage and rotation of keys. It contradicts the requirement for minimal operational overhead and no code changes. While it can provide strong confidentiality, it is not the appropriate approach when the provider's managed encryption is acceptable.
- ✓
Enable server-side encryption with provider-managed keys on the bucket, which automatically encrypts objects at rest.
Why this is correct
Server-side encryption with provider-managed keys encrypts objects at rest and the cloud provider handles key storage, rotation, and access transparently. The application continues to read and write objects without modification, meeting the minimal-overhead and no-code-change requirements. This directly satisfies the policy that data be encrypted at rest while keeping operations simple.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.