Courseiva
Cloud Data Security →easyMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security team needs to ensure that all data in transit between on-premises systems and the cloud is encrypted. Which TWO options should they consider? (Choose two.)

⚠ Common exam trap

CCSP often tests the distinction between encryption in transit and at rest, and candidates may mistakenly select server-side encryption with CMEK (which is for data at rest) or signed URLs (which are for access control) when asked about data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up a VPN between on-premises and cloud

Option A is correct because a VPN (typically IPsec or SSL/TLS-based) creates an encrypted tunnel over the public internet between on-premises networks and the cloud, protecting all data in transit at the network layer. Option E is correct because enforcing TLS 1.2 or higher on all API calls encrypts application-layer traffic end-to-end, ensuring data in transit between clients and cloud services is protected with strong ciphers. Option B is incorrect because signed URLs only grant time-limited access to specific resources; they do not encrypt the data in transit. Option C is incorrect because bucket versioning preserves object versions for recovery and durability, not encryption. Option D is incorrect because server-side encryption with CMEK protects data at rest, not data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set up a VPN between on-premises and cloud

    Why this is correct

    An IPsec VPN encrypts all traffic traversing the tunnel between on-premises gateways and cloud networks, covering every protocol rather than individual sessions. This satisfies the requirement that all data in transit be encrypted, since the tunnel provides blanket protection regardless of application.

  • ✗

    Use signed URLs for access

    Why it's wrong here

    Signed URLs grant time-limited access to a specific object, so they authorise retrieval without encrypting the connection between on-premises systems and the cloud. They are tempting because they secure object access, but transport encryption requires TLS or a VPN/IPsec tunnel protecting data in transit.

  • ✗

    Enable bucket versioning

    Why it's wrong here

    Bucket versioning retains multiple object revisions to support recovery from overwrites or deletions; it does not encrypt the network path between on-premises systems and cloud storage. It is tempting because it protects stored data, but the requirement concerns data in transit, which needs TLS or an IPsec VPN.

  • ✗

    Enable server-side encryption with CMEK

    Why it's wrong here

    Server-side encryption with CMEK protects data at rest within the cloud storage layer, not data in transit across the network boundary between on-premises systems and the cloud. It is tempting because CMEK gives the customer control over the encryption key lifecycle, which is often mandated for compliance; however, it would be the correct choice for a scenario requiring the organisation to manage its own keys for encrypting stored objects, such as a regulatory requirement for key rotation or revocation.

  • ✓

    Use TLS 1.2+ for all API calls

    Why this is correct

    TLS 1.2 or higher encrypts API calls in transit using certificates and negotiated ciphersuites, protecting data between clients and cloud endpoints. This satisfies the requirement for encrypted transit for programmatic access, complementing network-layer encryption with application-layer protection.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.