Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A company is migrating its on-premises database to a cloud-based database-as-a-service (DBaaS) offering. The security team wants to ensure that the data remains encrypted at rest and that they retain control over the encryption keys. Which cloud data security concept should they implement?

⚠ Common exam trap

The trap here is equating encryption at rest with customer key control; provider-managed TDE encrypts data but does not give the customer key ownership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Bring Your Own Key (BYOK) integrated with the cloud provider's key management service.

BYOK enables the company to generate and control its own encryption keys while leveraging the cloud provider's KMS for key storage and operations. This meets the need for encryption at rest with customer-controlled keys, unlike provider-managed TDE or transit encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL/TLS encryption for data in transit between the application and the database.

    Why it's wrong here

    SSL/TLS protects data in transit, not at rest. The requirement specifically asks for encryption at rest with customer-controlled keys. While important, TLS does not address the storage encryption or key control needs described in the scenario.

  • ✗

    Database auditing and logging to monitor access to sensitive data.

    Why it's wrong here

    Auditing and logging provide visibility into who accessed data but do not encrypt data at rest or give the company control over encryption keys. These are detective controls, not preventive encryption controls, and do not satisfy the stated requirement.

  • ✓

    Bring Your Own Key (BYOK) integrated with the cloud provider's key management service.

    Why this is correct

    BYOK allows the company to generate and manage its own encryption keys while using the cloud provider's key management service for storage and lifecycle operations. This gives the company control over the keys and satisfies the requirement for encryption at rest with customer-controlled keys.

  • ✗

    Transparent Data Encryption (TDE) with keys managed by the cloud provider.

    Why it's wrong here

    TDE with provider-managed keys encrypts data at rest, but the cloud provider controls the keys. This does not meet the requirement to retain control over the encryption keys. The company needs to manage the keys themselves, not delegate to the provider.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.