CCSP Cloud Data Security Practice Question
A cloud security administrator is configuring encryption for a new cloud storage bucket that will hold archived logs. The logs are not highly sensitive but must be encrypted at rest to meet a compliance requirement. The administrator wants to minimize operational overhead and does not need to manage keys. Which encryption option is MOST appropriate?
⚠ Common exam trap
The trap here is over-engineering the solution by assuming that any encryption requirement necessitates customer-managed or client-side keys, when provider-managed keys are sufficient for low-sensitivity data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
For non-sensitive data with a simple encryption-at-rest requirement and a desire to minimize operational overhead, provider-managed server-side encryption is the most appropriate. It is automatic, requires no key management, and meets compliance. Customer-managed or client-side options add unnecessary complexity and cost without providing additional value for this use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side encryption with customer-managed keys stored in a cloud KMS.
Why it's wrong here
While this provides more control over keys, it introduces operational overhead such as key rotation, access policies, and monitoring. The scenario explicitly states the administrator wants to minimize overhead and does not need to manage keys. Therefore, this option is unnecessarily complex for the given requirements. It is better suited for sensitive data where key control is a priority.
- ✗
Server-side encryption with customer-provided keys (SSE-C) supplied with each API request.
Why it's wrong here
SSE-C requires the customer to provide and manage encryption keys for every request, which increases operational burden and risk of key loss. It does not align with the requirement to minimize overhead. Additionally, it provides no benefit over provider-managed keys for non-sensitive data, and it complicates access patterns. It is typically used when the customer must control keys but does not want to implement full client-side encryption.
- ✗
Client-side encryption with keys stored on-premises in a hardware security module (HSM).
Why it's wrong here
Client-side encryption with on-premises HSMs adds significant operational complexity, including key management, secure key distribution, and application changes. It is designed for highly sensitive data where the cloud provider must not access plaintext. For archived logs that are not highly sensitive, this approach is overkill and contradicts the goal of minimizing overhead.
- ✓
Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
Why this is correct
Server-side encryption with provider-managed keys automatically encrypts data at rest and handles key management, rotation, and storage. It requires no customer action and imposes minimal operational overhead. Since the logs are not highly sensitive and the requirement is simply encryption at rest, this option meets the compliance need without additional complexity. It is the default and most cost-effective approach for such scenarios.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.