easyMultiple Choice
CCSP Practice Question: Migrating its customer database to a cloud object…
A company is migrating its customer database to a cloud object storage service. The database contains personally identifiable information (PII). The security team requires that all data be encrypted at rest and that the company retains exclusive control over the encryption keys. Which solution BEST meets these requirements?
⚠ Common exam trap
It's easy for candidates to confuse SSE-C with client-side encryption, assuming that providing your own key to the server (SSE-C) gives you exclusive control, but in SSE-C the cloud provider still handles the encryption/decryption process and may retain the key in memory, whereas client-side encryption ensures the provider never sees the key at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use client-side encryption with customer-managed keys stored on-premises.
Client-side encryption with customer-managed keys stored on-premises ensures that the encryption keys never leave the company's control, and the data is encrypted before it is uploaded to the cloud object storage service. This satisfies both the requirement for encryption at rest and exclusive key control, as the cloud provider never has access to the plaintext keys or the ability to decrypt the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use server-side encryption with cloud provider-managed keys (SSE-S3).
Why it's wrong here
SSE-S3 has the cloud provider generate, store and rotate the data keys, so the company does not retain exclusive control; the provider can access plaintext. It suits workloads without key-ownership mandates. The requirement for exclusive key control demands client-side encryption or a customer-managed key service instead.
- ✗
Use SSL/TLS encryption for data in transit only.
Why it's wrong here
SSL/TLS protects data in transit, so it leaves data unencrypted at rest in object storage and gives the company no key custody at all. It is tempting because TLS is the standard control for protecting data moving between clients and services, and would be the right answer if the requirement were transport confidentiality rather than encryption at rest with exclusive key control.
- ✓
Use client-side encryption with customer-managed keys stored on-premises.
Why this is correct
Client-side encryption encrypts data before it reaches the object store, and keys held on-premises mean the provider never possesses them. This satisfies both stem requirements: encryption at rest and exclusive customer control over the encryption keys.
- ✗
Use server-side encryption with customer-provided keys (SSE-C).
Why it's wrong here
SSE-C has the customer supply the key with each request, but the provider still performs the encryption and holds the key transiently in memory, so exclusive control is not retained. It suits scenarios accepting provider-side cryptographic operations. Client-side encryption, where keys never leave the company, meets the exclusive-control requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.