CCSP Cloud Data Security Practice Question
A cloud security architect is designing a key management strategy for a hybrid cloud environment. The organization requires that encryption keys never leave their on-premises hardware security module (HSM) due to strict regulatory mandates, yet cloud services must be able to perform encryption operations on data at rest. Which key management approach meets these requirements?
⚠ Common exam trap
The trap is conflating BYOK with HYOK — both involve 'your own key,' but only HYOK keeps the key physically on-premises. Candidates who skim the question miss the phrase 'keys never leave their on-premises HSM.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hold Your Own Key (HYOK)
HYOK (Hold Your Own Key) keeps the master key material inside the customer's on-premises HSM and never exports it to the cloud provider. The cloud service sends cryptographic operations (encrypt/decrypt) to the on-prem HSM via a secure channel, so keys never leave the customer's control while still enabling encryption of cloud data at rest. This satisfies the regulatory mandate that keys remain on-premises.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-managed encryption keys (CMEK)
Why it's wrong here
CMEK stores key material inside the provider's KMS, so keys do reside in cloud infrastructure, breaching the mandate that they never leave the on-premises HSM. It is tempting because CMEK gives the customer control over key rotation and access policies, and would suit scenarios demanding customer-controlled lifecycle without a residency constraint.
- ✓
Hold Your Own Key (HYOK)
Why this is correct
HYOK retains key material within the customer's on-premises HSM, with cryptographic operations performed locally or via a proxy, so keys never leave the HSM. This satisfies the regulatory mandate while still permitting encryption of cloud data at rest.
- ✗
Cloud provider default encryption
Why it's wrong here
Provider default encryption places key generation, storage and rotation entirely with the cloud provider, so keys sit in provider HSMs and the customer exercises no control, failing the on-premises residency mandate. It is tempting as a zero-configuration baseline protecting data at rest when no regulatory key-custody requirement applies.
- ✗
Bring Your Own Key (BYOK)
Why it's wrong here
BYOK imports customer-generated key material into the provider's KMS, so the keys then reside in cloud HSMs, violating the requirement that they never leave the on-premises HSM. It is tempting because BYOK gives the customer control over key generation and rotation, and would be correct where keys may be imported but not held externally.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.