Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud security administrator is configuring access to a cloud storage bucket that contains regulated data. The administrator needs to ensure that data is encrypted at rest using keys that are automatically rotated every 90 days. Which cloud service feature should the administrator use?

⚠ Common exam trap

The trap here is assuming that provider-managed keys allow custom rotation schedules, when in fact the rotation interval is controlled by the provider and not configurable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-side encryption with customer-managed keys in a cloud KMS.

Customer-managed keys in a cloud KMS enable automatic rotation with a configurable schedule, satisfying the 90-day requirement. Provider-managed keys rotate automatically but without customer control over the interval. Client-side and customer-provided keys require manual rotation. Thus, the KMS option is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Client-side encryption with a locally stored key.

    Why it's wrong here

    Client-side encryption shifts key management to the customer, but automatic rotation every 90 days would require custom tooling and is not a built-in feature of the cloud service. The administrator would need to implement rotation manually, which is not the intended use of a cloud service feature for this scenario.

  • ✗

    Server-side encryption with customer-provided keys (SSE-C).

    Why it's wrong here

    With SSE-C, the customer provides the key with each request, and the cloud provider does not store the key. Automatic rotation is not supported because the provider has no key to rotate. The administrator would have to manage rotation entirely, which does not meet the requirement for automatic rotation.

  • ✓

    Server-side encryption with customer-managed keys in a cloud KMS.

    Why this is correct

    Customer-managed keys in a cloud KMS allow the administrator to configure automatic rotation with a custom schedule, such as every 90 days. This meets the requirement for controlled rotation. The administrator retains control over the key lifecycle while benefiting from server-side encryption.

  • ✗

    Server-side encryption with provider-managed keys (SSE-S3 or equivalent).

    Why it's wrong here

    Provider-managed keys are automatically rotated by the provider, but the rotation interval is typically not configurable and may not meet the specific 90-day requirement. The administrator needs control over rotation frequency. This option does not provide the necessary control over key rotation scheduling.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.