Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security architect is designing a multi-tenant SaaS platform hosted on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application instance in one tenant's environment cannot decrypt another tenant's data. The architect wants to use AWS Key Management Service (KMS) to manage encryption keys. Which approach BEST meets this requirement?

⚠ Common exam trap

The trap here is assuming that application-level tenant ID checks or a shared KMS key with rotation provide sufficient isolation, when true cryptographic isolation requires distinct keys with scoped permissions per tenant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a separate AWS KMS customer managed key per tenant, with a key policy that grants decrypt permission only to that tenant's application role, and store the tenant's data encrypted under its own key.

Cryptographic isolation in a multi-tenant cloud environment requires that each tenant's data be protected by a distinct key whose usage is governed by least-privilege policies. Per-tenant AWS KMS customer managed keys with narrowly scoped key policies ensure that a compromised application instance can only decrypt its own tenant's data. Shared keys, even with rotation or application-level checks, do not prevent cross-tenant decryption if credentials are compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS KMS with a single customer managed key, but enable automatic key rotation every 90 days and require all tenants to use the same key alias for encryption and decryption.

    Why it's wrong here

    Key rotation changes the backing key material but does not provide tenant isolation; all tenants still share the same logical KMS key and its permissions. A compromised instance with decrypt permission on that key can decrypt any tenant's data. Rotation addresses key lifetime, not multi-tenant cryptographic separation.

  • ✗

    Use a single AWS KMS customer managed key with a key policy that grants decrypt permissions to all tenant application roles, and rely on application-level tenant ID checks before decryption.

    Why it's wrong here

    A single KMS key shared across tenants means any compromised application instance with decrypt permission can decrypt any tenant's ciphertext if it obtains the ciphertext. Application-level checks are not cryptographic isolation and can be bypassed. This fails the requirement that a compromised instance cannot decrypt another tenant's data.

  • ✓

    Create a separate AWS KMS customer managed key per tenant, with a key policy that grants decrypt permission only to that tenant's application role, and store the tenant's data encrypted under its own key.

    Why this is correct

    Per-tenant KMS keys with scoped key policies enforce cryptographic isolation at the key-management layer. Even if an application instance is compromised, its IAM role only has decrypt permission on its own tenant's key, so it cannot decrypt other tenants' ciphertext. This directly satisfies the requirement.

  • ✗

    Store all tenant data in a single Amazon S3 bucket encrypted with SSE-S3, and use S3 bucket policies to restrict each tenant's application role to its own prefix.

    Why it's wrong here

    SSE-S3 uses an AWS-managed key that the customer does not control, and bucket policies restrict access to prefixes but do not provide cryptographic isolation. A compromised instance with valid credentials could still access other prefixes if policy is misconfigured, and the same key encrypts all objects. This does not meet the stated requirement.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.