Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?

⚠ Common exam trap

The trap here is assuming that encryption at rest with any key management scheme automatically solves data remanence, when only per-tenant keys enabling cryptographic erasure actually eliminate cross-tenant recovery risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.

Cryptographic erasure with per-tenant customer-managed keys is the strongest control against storage remanence in multi-tenant environments because destroying the key renders residual ciphertext unrecoverable. Provider-managed shared keys, memory scrubbing, and QoS controls do not address persistent-block reuse by other tenants, leaving confidentiality risk unresolved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable server-side encryption with a single provider-managed key for the whole storage service.

    Why it's wrong here

    A shared provider-managed key protects data from physical theft but does not allow per-tenant cryptographic erasure. If blocks are reallocated, residual ciphertext may still be recoverable with the same key, so cross-tenant remanence risk remains. It also reduces tenant control over key lifecycle.

  • ✗

    Implement storage QoS and IOPS throttling to isolate tenant workloads on shared volumes.

    Why it's wrong here

    QoS and throttling address noisy-neighbor performance and availability concerns, not data confidentiality or remanence. They do not alter how data is written, keyed, or destroyed on disk, so a subsequent tenant could still recover residual data. This control belongs to a performance isolation discussion.

  • ✗

    Rely on the hypervisor's memory scrubbing between VM lifecycles to prevent data leakage.

    Why it's wrong here

    Memory scrubbing addresses volatile RAM reuse between VM instances, not persistent storage remanence. It does nothing to prevent leftover blocks on shared storage from being read by another tenant. The scenario explicitly targets storage-layer remanence, so this control is misaligned.

  • ✓

    Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.

    Why this is correct

    Per-tenant customer-managed keys allow the provider to cryptographically shred data by destroying the tenant-specific key, so remanence risk is eliminated even if physical blocks are later reallocated to another tenant. This satisfies CCSP expectations for data isolation and secure disposal in multi-tenant storage.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.