Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application process cannot read another tenant's data. The architect plans to use AWS Key Management Service (KMS) with tenant-specific keys. Which of the following is the MOST critical security control to implement to achieve this isolation?

⚠ Common exam trap

The trap here is assuming that access control policies alone (like bucket policies or IAM) provide sufficient isolation, when cryptographic separation via distinct keys is required to prevent a compromised process from decrypting other tenants' data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a separate KMS customer managed key per tenant and enforce strict IAM policies that limit each tenant's application role to only its own key.

The scenario requires cryptographic isolation so that a compromised process cannot read another tenant's data. Using a separate KMS customer managed key per tenant ensures that data is encrypted with distinct keys, and strict IAM policies limit each tenant's role to only its own key. This combination creates a strong boundary. Other options are either hygiene practices or detective controls that do not prevent cross-tenant access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store all tenant data in a single S3 bucket with a bucket policy that restricts access by tenant ID prefix.

    Why it's wrong here

    A bucket policy based on prefix is an access control mechanism, not cryptographic isolation. If an application process is compromised, it may still have permissions to read objects outside its tenant prefix if the policy is misconfigured or if the process can assume a broader role. It does not provide the strong separation required.

  • ✗

    Enable automatic key rotation for all KMS customer managed keys.

    Why it's wrong here

    Automatic key rotation reduces the window of exposure if a key is compromised, but it does not enforce isolation between tenants. A compromised application process with access to the KMS key could still decrypt any tenant's data encrypted under that key. Rotation alone does not provide cryptographic separation; it is a hygiene practice, not an isolation boundary.

  • ✓

    Use a separate KMS customer managed key per tenant and enforce strict IAM policies that limit each tenant's application role to only its own key.

    Why this is correct

    Using a distinct KMS key per tenant creates a cryptographic boundary: data encrypted under one key cannot be decrypted with another. Coupling this with least-privilege IAM policies ensures that a compromised process can only access its own tenant's key. This directly prevents cross-tenant data access, satisfying the isolation requirement.

  • ✗

    Enable AWS CloudTrail logging for all KMS API calls and monitor for anomalous decrypt operations.

    Why it's wrong here

    CloudTrail logging and monitoring are detective controls that help identify unauthorized access after it occurs. They do not prevent a compromised process from decrypting another tenant's data. While valuable for auditing, they do not enforce the cryptographic isolation that the scenario demands.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.