Courseiva
Cloud Data Security →mediumMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security architect is designing a key management strategy to meet regulatory requirements for key separation and tamper evidence. Which TWO of the following are benefits of using hardware security modules (HSMs) backing a cloud KMS? (Select TWO.)

⚠ Common exam trap

The trap is selecting plausible-sounding but incorrect benefits like 'reduced latency' or 'automatic rotation.' Candidates must distinguish inherent HSM properties (tamper resistance, FIPS validation) from KMS policy features (rotation) and from performance claims that are usually false.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compliance with FIPS 140-2 Level 3 or higher

Option A is correct because HSMs backing a cloud KMS are validated to FIPS 140-2 (or FIPS 140-3) Level 3 or higher, which requires physical tamper resistance, identity-based authentication, and role separation — directly satisfying the regulatory key-separation and tamper-evidence requirements described. Option E is correct because HSM hardware is tamper-resistant and tamper-evident: keys are generated and used inside the cryptographic boundary and cannot be extracted in plaintext, with mechanisms that zeroize keys and leave evidence if the module is physically breached. Option B is wrong because HSMs protect keys but do not remove the need for customer-managed keys — in fact, customer-managed keys are often used with HSM-backed KMS to meet separation-of-duties requirements. Option C is wrong because HSM-backed operations typically add network and hardware round-trip latency compared with software-only key stores, not reduce it. Option D is wrong because automatic key rotation is a KMS policy feature, not an inherent benefit of HSM backing, and many regulations still require customer-controlled or explicitly configured rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Compliance with FIPS 140-2 Level 3 or higher

    Why this is correct

    HSMs validated to FIPS 140-2 Level 3 or higher provide physical tamper evidence and identity-based authentication, directly satisfying the stem's tamper-evidence requirement. Level 3's tamper-response mechanisms destroy keys on intrusion attempts, unlike software-based key stores. This certification also underpins key separation by enforcing cryptographic boundaries between tenants and roles within Microsoft Entra ID-integrated KMS deployments.

  • ✗

    Eliminates the need for customer-managed keys

    Why it's wrong here

    HSMs protect key material but do not remove the need for customer-managed keys; they underpin them. This option is tempting because HSM-backed KMS keys are customer-controlled, yet the benefit sought is tamper-evident hardware protection and key separation, not elimination of customer-managed keys.

  • ✗

    Reduced latency for encryption operations

    Why it's wrong here

    HSM-backed keys add cryptographic processing and network round trips, so latency typically rises rather than falls; performance is not the regulatory benefit sought. Reduced latency tempts because dedicated hardware sounds faster, but the requirement is key separation and tamper evidence, which HSMs provide through isolated, hardened key storage.

  • ✗

    Automatic key rotation without customer intervention

    Why it's wrong here

    Rotation is a KMS scheduling feature available regardless of HSM backing, so it does not depend on hardware modules. HSMs are tempting because they provide key separation and tamper evidence through FIPS 140-validated hardware boundaries, which is what the scenario's regulatory requirements actually demand.

  • ✓

    Tamper-resistant key storage that prevents key extraction

    Why this is correct

    HSMs provide tamper-resistant hardware that detects and responds to physical intrusion, preventing key extraction even with host-level compromise. This directly satisfies the stem's tamper evidence requirement, since cryptographic keys remain sealed within validated hardware boundaries rather than exposed in software memory.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.