CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security architect is designing a workload that must store encryption keys in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. The workload runs on a major public cloud provider. The architect wants to minimize operational overhead while ensuring the keys never leave the HSM boundary. Which cloud service model should the architect select?
⚠ Common exam trap
The trap here is assuming that any encryption key store with encryption at rest meets the HSM requirement, when FIPS 140-2 Level 3 specifically demands tamper-resistant hardware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A cloud provider's managed Hardware Security Module (HSM) service offering dedicated, tamper-resistant HSM appliances.
The requirement is for a FIPS 140-2 Level 3 validated HSM with minimal operational overhead and keys that never leave the HSM. A managed HSM service provides dedicated, validated hardware while the provider handles maintenance and availability, satisfying both security and operational needs. Alternatives either lack hardware validation, export keys outside the boundary, or add unnecessary management burden.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A cloud provider's managed Hardware Security Module (HSM) service offering dedicated, tamper-resistant HSM appliances.
Why this is correct
A managed HSM service provides dedicated FIPS 140-2 Level 3 validated hardware, and the provider handles patching, scaling, and high availability. Keys are generated and stored inside the HSM boundary and cannot be exported in plaintext. This matches the requirement for minimal operational overhead while keeping keys within validated hardware, which is exactly what the architect needs.
- ✗
A software-based key management service that uses a shared, multi-tenant key store with encryption at rest.
Why it's wrong here
Software-based key management services typically rely on software cryptographic modules and multi-tenant storage, which do not meet the FIPS 140-2 Level 3 hardware requirement. Even when data is encrypted at rest, the keys are not protected by tamper-resistant hardware, so the key material could theoretically be exposed outside a validated boundary. This fails the stated HSM requirement.
- ✗
A cloud provider's virtual private cloud (VPC) with a customer-managed encryption key stored in the provider's object storage.
Why it's wrong here
Storing a customer-managed key in object storage, even encrypted, does not provide the tamper-resistant hardware protection of a FIPS 140-2 Level 3 HSM. Object storage is a data store, not a cryptographic boundary, and the key could be accessed by anyone with sufficient privileges. This approach fails both the hardware validation and key isolation requirements.
- ✗
An on-premises HSM connected to the cloud via a VPN tunnel, with keys replicated to the cloud provider's key vault.
Why it's wrong here
Replicating keys to a cloud key vault moves them outside the HSM boundary, violating the requirement that keys never leave the HSM. A VPN tunnel does not change the trust boundary of the key material. Additionally, managing on-premises hardware and replication adds operational overhead, which contradicts the goal of minimizing overhead.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.