CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?
⚠ Common exam trap
The trap here is assuming that encryption at rest with any key management scheme automatically solves data remanence, when only per-tenant keys enabling cryptographic erasure actually eliminate cross-tenant recovery risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.
Cryptographic erasure with per-tenant customer-managed keys is the strongest control against storage remanence in multi-tenant environments because destroying the key renders residual ciphertext unrecoverable. Provider-managed shared keys, memory scrubbing, and QoS controls do not address persistent-block reuse by other tenants, leaving confidentiality risk unresolved.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable server-side encryption with a single provider-managed key for the whole storage service.
Why it's wrong here
A shared provider-managed key protects data from physical theft but does not allow per-tenant cryptographic erasure. If blocks are reallocated, residual ciphertext may still be recoverable with the same key, so cross-tenant remanence risk remains. It also reduces tenant control over key lifecycle.
- ✗
Implement storage QoS and IOPS throttling to isolate tenant workloads on shared volumes.
Why it's wrong here
QoS and throttling address noisy-neighbor performance and availability concerns, not data confidentiality or remanence. They do not alter how data is written, keyed, or destroyed on disk, so a subsequent tenant could still recover residual data. This control belongs to a performance isolation discussion.
- ✗
Rely on the hypervisor's memory scrubbing between VM lifecycles to prevent data leakage.
Why it's wrong here
Memory scrubbing addresses volatile RAM reuse between VM instances, not persistent storage remanence. It does nothing to prevent leftover blocks on shared storage from being read by another tenant. The scenario explicitly targets storage-layer remanence, so this control is misaligned.
- ✓
Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.
Why this is correct
Per-tenant customer-managed keys allow the provider to cryptographically shred data by destroying the tenant-specific key, so remanence risk is eliminated even if physical blocks are later reallocated to another tenant. This satisfies CCSP expectations for data isolation and secure disposal in multi-tenant storage.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.